PT-2020-15933 · D Link · D-Link Dcs-2530L +1

Published

2020-09-02

·

Updated

2025-08-09

·

CVE-2020-25079

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DCS-2530L versions prior to 1.06.01 Hotfix D-Link DCS-2670L versions through 2.02
Description An issue exists in the
cgi-bin/ddns enc.cgi
file on D-Link DCS-2530L and DCS-2670L devices that allows authenticated command injection.
Recommendations D-Link DCS-2530L versions prior to 1.06.01 Hotfix: Update to version 1.06.01 Hotfix or later. D-Link DCS-2670L versions through 2.02: Update to a version later than 2.02.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-25079

Affected Products

D-Link Dcs-2530L
D-Link Dcs-2670L