CVE-2020-25079: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddnsenc.cgi allows authenticated command injection.
Other sources
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddnsenc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
D-Link DCS-2530Lfrom your environment.Discontinue product utilization for affected D-Link DCS-2530L devices if mitigations are unavailable (issue present before 1.06.01 Hotfix).
- Remove
Remove
D-Link DCS-2670Lfrom your environment.Discontinue product utilization for affected D-Link DCS-2670L devices if mitigations are unavailable (issue present through 2.02).
- Compensating control
If mitigation steps are unavailable, discontinue use of the affected D-Link IP camera products to address the authenticated command injection in cgi-bin/ddns_enc.cgi.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25079?
CVE-2020-25079 is classified as a high severity vulnerability due to the potential for authenticated command injection.
How do I fix CVE-2020-25079?
To fix CVE-2020-25079, update the firmware of your D-Link DCS-2530L to at least version 1.06.01 Hotfix or the DCS-2670L to at least version 2.03.
Which devices are affected by CVE-2020-25079?
CVE-2020-25079 affects the D-Link DCS-2530L before firmware version 1.06.01 Hotfix and DCS-2670L up to version 2.02.
What type of vulnerability is CVE-2020-25079?
CVE-2020-25079 is a command injection vulnerability that allows for the execution of arbitrary commands on affected devices.
Is there a workaround for CVE-2020-25079 while I wait for a fix?
The best workaround for CVE-2020-25079 is to limit network access to the device and monitor for any unauthorized access.