CVE-2020-25079: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-08-05. EPSS: 54% chance of exploitation in the next 30 days.
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
Affected products
- D-Link DCS-2530L Firmware: up to and including 1.05.05
- D-Link DCS-2670L Firmware: before 2.03.00 (fixed in 2.03.00)
- D-Link Dcs-4603 Firmware: before 1.04.02 (fixed in 1.04.02)
- D-Link Dcs-4622 Firmware: before 2.01.10 (fixed in 2.01.10)
- D-Link Dcs-4701e Firmware: before 2.03.01 (fixed in 2.03.01)
- D-Link Dcs-4703e Firmware: before 1.03.04 (fixed in 1.03.04)
- D-Link Dcs-4705e Firmware: before 1.03.02 (fixed in 1.03.02)
- D-Link Dcs-4802e Firmware: before 2.01.01 (fixed in 2.01.01)
- D-Link Dcs-p703 Firmware: any version
Published 2020-09-02. Last modified 2026-06-17.