A command injection vulnerability (CVE-2026-1419) has been identified in D-Link DCS700l version 1.03.09 within the Web Form Handler component. By manipulating the LightSensorControl argument in the /setDayNightMode file, a remote attacker can execute arbitrary commands.
A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.