D-Link Forums

Announcements => Security Advisories => Topic started by: GreenBay42 on October 31, 2018, 10:50:01 AM

Title: DCS-2630L IP Camera Security Report - Consumer Reports
Post by: GreenBay42 on October 31, 2018, 10:50:01 AM
Source --> https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10095 (https://securityadvisories.dlink.com/announcement/publication.aspx?name=SAP10095)

On October 31, 2018 Consumer Reports released a report that accused the DCS-2630L of a number of security issues.

Link: https://www.consumerreports.org/privacy/d-link-camera-poses-data-security-risk--consumer-reports-finds/ (https://www.consumerreports.org/privacy/d-link-camera-poses-data-security-risk--consumer-reports-finds/)

D-Link has already released a web portal update to eliminate risk of account enumeration. D-Link plans to release the following firmware versions to address and resolve the other reported issues.

Firmware version 1.05 (mid-November) for Denial of Service, CSRF Protection, and Profiling
Firmware version 1.06 (late December) to strengthen Authentication and Password

Please check the D-Link Support website regularly for updates. If the camera is registered with mydlink cloud service, the user will be notified and will be able to update the camera through the mydlink mobile application.