A remote code execution (RCE) vulnerability has been detected in the latest firmware of the D-Link DCS-930L Network Cloud Camera. The vulnerability allows code injection which lets the attacker set a custom password, granting remote access to the camera feed. The older models will have to be removed from the market, as new releases will be available only for active products. Older models can still be used at users risk, but older models must be removed. The problem is disturbing considering IoT and network embedded devices have been widely embraced by various industries, including medical devices, nuclear power plants and traffic systems.”]

