CVE-2020-25079

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-2530l:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dlink:dcs-2670l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-2670l:-:*:*:*:*:*:*:*

History

06 Aug 2025, 20:42

Type Values Removed Values Added
References () https://support.dlink.com/productinfo.aspx?m=DCS-2530L - () https://support.dlink.com/productinfo.aspx?m=DCS-2530L - Product
First Time Dlink dcs-4603 Firmware
Dlink dcs-4705e
Dlink dcs-4703e Firmware
Dlink dcs-4703e
Dlink dcs-4622 Firmware
Dlink dcs-4701e Firmware
Dlink dcs-4701e
Dlink dcs-p703 Firmware
Dlink dcs-4603
Dlink dcs-4802e Firmware
Dlink dcs-4802e
Dlink dcs-4622
Dlink dcs-4705e Firmware
Dlink dcs-p703
CPE cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*

05 Aug 2025, 18:15

Type Values Removed Values Added
References
  • () https://support.dlink.com/productinfo.aspx?m=DCS-2530L -

Information

Published : 2020-09-02 16:15

Updated : 2025-08-06 20:42


NVD link : CVE-2020-25079

Mitre link : CVE-2020-25079

CVE.ORG link : CVE-2020-25079


JSON object : View

Products Affected

dlink

  • dcs-2530l_firmware
  • dcs-4705e
  • dcs-4622_firmware
  • dcs-4622
  • dcs-4701e
  • dcs-p703
  • dcs-4705e_firmware
  • dcs-2670l
  • dcs-4703e
  • dcs-4701e_firmware
  • dcs-4603_firmware
  • dcs-4802e
  • dcs-2530l
  • dcs-p703_firmware
  • dcs-4703e_firmware
  • dcs-4802e_firmware
  • dcs-2670l_firmware
  • dcs-4603
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')