A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Thu, 05 Feb 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware
CPEs cpe:2.3:h:dlink:dcs-700l:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-700l_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dcs-700l
Dlink dcs-700l Firmware

Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dcs-700l
Vendors & Products D-link
D-link dcs-700l

Wed, 28 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DCS-700L Music File Upload Service setUploadMusic uploadmusic path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 2.2, 'vector': 'AV:A/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-01-28T21:44:07.743Z

Reserved: 2026-01-28T13:28:05.800Z

Link: CVE-2026-1532

cve-icon Vulnrichment

Updated: 2026-01-28T21:44:04.014Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T21:16:10.703

Modified: 2026-02-05T16:57:12.147

Link: CVE-2026-1532

cve-icon Redhat

No data.