cbcvebase.
CVE-2020-25078
published 2020-09-02

CVE-2020-25078: An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for…

PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-08-26
Exploited in the wild
EPSS
97.90%
99.9th percentile
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Affected

8 ranges
VendorProductVersion rangeFixed in
dlinkdcs-2530l_firmware<= 1.05.05
dlinkdcs-2670l_firmware< 2.03.002.03.00
dlinkdcs-4603_firmware< 1.04.021.04.02
dlinkdcs-4622_firmware< 2.01.102.01.10
dlinkdcs-4701e_firmware< 2.03.012.03.01
dlinkdcs-4703e_firmware< 1.03.041.03.04
dlinkdcs-4705e_firmware< 1.03.021.03.02
dlinkdcs-4802e_firmware< 2.01.012.01.01

Detection & IOCsextracted from sources · hover to see the quote

url/config/getuser?index=0
path/config/getuser
yara
matchers: words: ["name=", "pass="] condition: and; header words: ["text/plain"]; status: 200
  • Monitor for scanning activity against TCP ports 23, 26, 554, 2323, 567, 5523, 8080, 9530, and 56575 on IoT/camera devices, which are the ports targeted in the HiatusRAT campaign exploiting CVE-2020-25078.
  • Compromised devices are converted into SOCKS5 proxies for C2 communication; detect unusual SOCKS5 proxy traffic originating from camera/DVR devices as a post-exploitation indicator.
  • ·Vulnerability affects D-Link DCS-2530L before firmware version 1.06.01 Hotfix and DCS-2670L through firmware version 2.02 only; patched versions are not vulnerable.
  • ·Affected devices may be end-of-life (EoL) or end-of-service (EoS); a patch may not be available for all affected models, requiring device replacement rather than patching.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.