An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
References
Link | Resource |
---|---|
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | Patch Vendor Advisory |
https://twitter.com/Dogonsecurity/status/1273251236167516161 | Third Party Advisory Broken Link |
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | Patch Vendor Advisory |
https://twitter.com/Dogonsecurity/status/1273251236167516161 | Third Party Advisory Broken Link |
https://support.dlink.com/productinfo.aspx?m=DCS-2530L | Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
06 Aug 2025, 20:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://twitter.com/Dogonsecurity/status/1273251236167516161 - Third Party Advisory, Broken Link | |
References | () https://support.dlink.com/productinfo.aspx?m=DCS-2530L - Product | |
First Time |
Dlink dcs-4603 Firmware
Dlink dcs-4705e Dlink dcs-4703e Firmware Dlink dcs-4703e Dlink dcs-4622 Firmware Dlink dcs-4701e Firmware Dlink dcs-4701e Dlink dcs-p703 Firmware Dlink dcs-4603 Dlink dcs-4802e Firmware Dlink dcs-4802e Dlink dcs-4622 Dlink dcs-4705e Firmware Dlink dcs-p703 |
|
CPE | cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:* |
05 Aug 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2020-09-02 16:15
Updated : 2025-08-06 20:42
NVD link : CVE-2020-25078
Mitre link : CVE-2020-25078
CVE.ORG link : CVE-2020-25078
JSON object : View
Products Affected
dlink
- dcs-2530l_firmware
- dcs-4705e
- dcs-4622_firmware
- dcs-4622
- dcs-4701e
- dcs-p703
- dcs-4705e_firmware
- dcs-2670l
- dcs-4703e
- dcs-4603_firmware
- dcs-4802e
- dcs-2530l
- dcs-p703_firmware
- dcs-4703e_firmware
- dcs-4802e_firmware
- dcs-4701e_firmware
- dcs-2670l_firmware
- dcs-4603
CWE