CVE-2020-25078: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-08-05. EPSS: 97.5% chance of exploitation in the next 30 days.
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
Affected products
- D-Link DCS-2530L Firmware: up to and including 1.05.05
- D-Link DCS-2670L Firmware: before 2.03.00 (fixed in 2.03.00)
- D-Link Dcs-4603 Firmware: before 1.04.02 (fixed in 1.04.02)
- D-Link Dcs-4622 Firmware: before 2.01.10 (fixed in 2.01.10)
- D-Link Dcs-4701e Firmware: before 2.03.01 (fixed in 2.03.01)
- D-Link Dcs-4703e Firmware: before 1.03.04 (fixed in 1.03.04)
- D-Link Dcs-4705e Firmware: before 1.03.02 (fixed in 1.03.02)
- D-Link Dcs-4802e Firmware: before 2.01.01 (fixed in 2.01.01)
- D-Link Dcs-p703 Firmware: any version
Published 2020-09-02. Last modified 2026-06-17.