PT-2020-15933 · D Link · D-Link Dcs-2670L +1

Published

2020-09-02

·

Updated

2025-08-06

·

CVE-2020-25079

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

D-Link DCS-2530L versions prior to 1.06.01 Hotfix

D-Link DCS-2670L versions prior to 2.03

Description:

An issue was discovered that allows authenticated command injection through the cgi-bin/ddns enc.cgi endpoint.

Recommendations:

For D-Link DCS-2530L versions prior to 1.06.01 Hotfix, update to version 1.06.01 Hotfix or later.

For D-Link DCS-2670L versions prior to 2.03, update to version 2.03 or later.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-25079

Affected Products

D-Link Dcs-2530L
D-Link Dcs-2670L