cbcvebase.
CVE-2020-25079
published 2020-09-02

CVE-2020-25079: An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2025-08-26
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

Affected

8 ranges
VendorProductVersion rangeFixed in
dlinkdcs-2530l_firmware<= 1.05.05
dlinkdcs-2670l_firmware< 2.03.002.03.00
dlinkdcs-4603_firmware< 1.04.021.04.02
dlinkdcs-4622_firmware< 2.01.102.01.10
dlinkdcs-4701e_firmware< 2.03.012.03.01
dlinkdcs-4703e_firmware< 1.03.041.03.04
dlinkdcs-4705e_firmware< 1.03.021.03.02
dlinkdcs-4802e_firmware< 2.01.012.01.01

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH