PT-2020-15932 · D Link · D-Link Dcs-2670L +1
Fenix
·
Published
2020-09-02
·
Updated
2025-08-06
·
CVE-2020-25078
7.5
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
D-Link DCS-2530L versions prior to 1.06.01 Hotfix
D-Link DCS-2670L versions prior to 2.02
Description:
An issue exists in D-Link DCS-2530L and DCS-2670L devices that allows for remote administrator password disclosure. The `/config/getuser` API endpoint is unauthenticated, enabling unauthorized access to administrator credentials. This vulnerability is actively exploited in the wild, as indicated by reports of exploitation by the HiatusRAT actor targeting web cameras and DVRs.
Recommendations:
D-Link DCS-2530L versions prior to 1.06.01 Hotfix: Update to version 1.06.01 Hotfix or later.
D-Link DCS-2670L versions prior to 2.02: Update to version 2.02 or later.
Exploit
Fix
Related Identifiers
Affected Products
References · 16
- 🔥 https://github.com/MzzdToT/CVE-2020-25078⭐ 4 🔗 3 · Exploit
- 🔥❌ https://github.com/S0por/CVE-2020-25078 · Exploit, Deleted
- https://nvd.nist.gov/vuln/detail/CVE-2020-25078 · Security Note
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 · Security Note, Vendor Advisory
- https://support.dlink.com/productinfo.aspx?m=DCS-2530L · Security Note
- https://twitter.com/CounterTheFraud/status/1880475023229550850 · Twitter Post
- https://twitter.com/the_yellow_fall/status/1952910723568549978 · Twitter Post
- https://twitter.com/The_Cyber_News/status/1952920903874175344 · Twitter Post
- https://t.me/cybersecuritytechnologies/3057 · Telegram Post
- https://twitter.com/Dogonsecurity/status/1273251236167516161 · Note
- https://twitter.com/johndjohnson/status/1870101204967063570 · Twitter Post
- https://twitter.com/ScyScan/status/1952807122456178821 · Twitter Post
- https://twitter.com/fernandokarl/status/1953047226470539749 · Twitter Post
- https://t.me/aptreports/14917 · Telegram Post
- https://twitter.com/rst_cloud/status/1869681143101989317 · Twitter Post