CVE-2020-25078: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
Other sources
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25078?
CVE-2020-25078 is considered a high severity vulnerability due to the potential for remote administrator password disclosure without authentication.
How do I fix CVE-2020-25078?
To fix CVE-2020-25078, update the D-Link DCS-2530L firmware to version 1.06.01 Hotfix or the DCS-2670L firmware to version 2.02 or later.
What systems are affected by CVE-2020-25078?
CVE-2020-25078 affects D-Link DCS-2530L devices with firmware versions prior to 1.06.01 Hotfix and DCS-2670L devices with firmware versions before 2.02.
Is it possible to exploit CVE-2020-25078 remotely?
Yes, CVE-2020-25078 can be exploited remotely, allowing attackers to gain unauthorized access to the administrator password.
What are the implications of CVE-2020-25078 for users?
Users affected by CVE-2020-25078 may experience unauthorized access to their D-Link camera settings and risk having their devices compromised.