CVE-2020-25078
D-Link · exploited in the wild
- Published
- 2 September 2020
- Last modified
- 17 June 2026
- CVSS
- 7.5 v3.1
- Severity
- high
- EPSS
- 97.9% (100th pct)
- CISA KEV
- Added 5 August 2025 KEV
- NVD status
- Analyzed
- Weaknesses
- None assigned
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
Exploitation
Added to the CISA Known Exploited Vulnerabilities catalogue on 5 August 2025, with a remediation due date of 26 August 2025 for US federal civilian agencies. CISA records no known ransomware campaign use.
Required action as published by CISA: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| DCS-2530L | D-Link | IP camera | <= 1.00.21, <= 1.05.05 |
| DCS-2670L | D-Link | IP camera | < 2.03.00 |
| DCS-4603 | D-Link | IP camera | < 1.04.02 |
| DCS-4622 | D-Link | IP camera | < 2.01.10 |
| DCS-4701E | D-Link | IP camera | < 2.03.01 |
| DCS-4703E | D-Link | IP camera | < 1.03.04 |
| DCS-4705E | D-Link | IP camera | < 1.03.02 |
| DCS-4802E | D-Link | IP camera | < 2.01.01 |
| Dcs-p703 | D-Link | IP camera | — |
References
Vendor advisory and patch
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180
- https://twitter.com/Dogonsecurity/status/1273251236167516161 third-party
- https://twitter.com/Dogonsecurity/status/1273251236167516161 third-party
- https://support.dlink.com/productinfo.aspx?m=DCS-2530L
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25078 government
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.