CVE-2020-25079
published 2020-09-02CVE-2020-25079: An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command…
PriorityP189high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-08-26
Exploited in the wild
EPSS
52.72%
98.9th percentile
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dcs-2530l_firmware | <= 1.05.05 | — |
| dlink | dcs-2670l_firmware | < 2.03.00 | 2.03.00 |
| dlink | dcs-4603_firmware | < 1.04.02 | 1.04.02 |
| dlink | dcs-4622_firmware | < 2.01.10 | 2.01.10 |
| dlink | dcs-4701e_firmware | < 2.03.01 | 2.03.01 |
| dlink | dcs-4703e_firmware | < 1.03.04 | 1.03.04 |
| dlink | dcs-4705e_firmware | < 1.03.02 | 1.03.02 |
| dlink | dcs-4802e_firmware | < 2.01.01 | 2.01.01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests targeting the cgi-bin/ddns_enc.cgi endpoint on D-Link DCS-2530L and DCS-2670L devices for command injection payloads in request parameters. ↗
- →Focus detection on authenticated sessions interacting with ddns_enc.cgi, as exploitation requires prior authentication. ↗
- ·Exploitation requires authentication; unauthenticated access alone is not sufficient to trigger the vulnerability. ↗
- ·Affected devices (DCS-2530L and DCS-2670L) may be end-of-life/end-of-service, meaning no further vendor patches may be issued; detection and network isolation are the primary mitigations. ↗
- ·Vulnerability affects DCS-2530L before firmware version 1.06.01 Hotfix and DCS-2670L through firmware version 2.02. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
cisa·2025-08-05·CVSS 8.8
CVE-2020-25079 [HIGH] CWE-77 D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
Vulnerability: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
Affected: D-Link DCS-2530L and DCS-2670L Devices
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.dlink.com/productinfo.aspx?m=DCS-2530L ; https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 ; https://nvd.nist.gov/vuln/detail/CVE-2020-25079
Remediation Due Date: 2025-08-26
GHSA
GHSA-w49v-8458-hh85: An issue was discovered on D-Link DCS-2530L before 1
ghsa_unreviewed·2022-05-24
CVE-2020-25079 [HIGH] CWE-77 GHSA-w49v-8458-hh85: An issue was discovered on D-Link DCS-2530L before 1
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
VulnCheck
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
vulncheck·2020·CVSS 8.8
CVE-2020-25079 [HIGH] CWE-77 D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Affected: D-Link DCS-2530L and DCS-2670L Devices
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.rapid7.com/cdn/assets/bltbd2f1cd70f9e3e7f/691360b9c91291146f1a5308/threat-landscape-report-q3-2025.pdf; https://www.loginsoft.com/reports/annual
No detection rules found.
No public exploits indexed.
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180https://twitter.com/Dogonsecurity/status/1271265152118259712https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180https://twitter.com/Dogonsecurity/status/1271265152118259712https://support.dlink.com/productinfo.aspx?m=DCS-2530Lhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079
2020-09-02
Published
2025-08-05
Added to CISA KEV
Exploited in the wild