cbcvebase.
CVE-2020-25078
published 2020-09-02

CVE-2020-25078: An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-08-26
Exploited in the wild
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Affected

8 ranges
VendorProductVersion rangeFixed in
dlinkdcs-2530l_firmware<= 1.05.05
dlinkdcs-2670l_firmware< 2.03.002.03.00
dlinkdcs-4603_firmware< 1.04.021.04.02
dlinkdcs-4622_firmware< 2.01.102.01.10
dlinkdcs-4701e_firmware< 2.03.012.03.01
dlinkdcs-4703e_firmware< 1.03.041.03.04
dlinkdcs-4705e_firmware< 1.03.021.03.02
dlinkdcs-4802e_firmware< 2.01.012.01.01

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH