CVE-2012-4046

The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"] value.

BUGTRAQ: http://seclists.org/bugtraq/2012/Dec/98
MISC: http://www.fishnetsecurity.com/6labs/blog/password-disclosure-d-link-surveillance-cameras-cve-2012-4046
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4046

12 years
256 countries
744k users
4988k calculations