CyberSec.Space Logo
Back to CVE Browser

CVE-2020-25078

Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
EPSS Score29.8750%
EPSS Percentile96.40th
PublishedSep 2, 2020
Last ModifiedNov 7, 2025

Vulnerability Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Affected Platforms (CPE)

πŸ’»
Dlink

Dcs 4603 Firmware

< 1.04.02
πŸ’»
Dlink

Dcs 4622 Firmware

< 2.01.10
πŸ’»
Dlink

Dcs 4701e Firmware

< 2.03.01
πŸ’»
Dlink

Dcs 4703e Firmware

< 1.03.04
πŸ’»
Dlink

Dcs 4705e Firmware

< 1.03.02
πŸ’»
Dlink

Dcs 4802e Firmware

< 2.01.01
πŸ’»
Dlink

Dcs P703 Firmware

All versions
πŸ’»
Dlink

Dcs 2530l Firmware

<= 1.05.05
πŸ’»
Dlink

Dcs 2670l Firmware

< 2.03.00

References & Advisories

Related Vulnerabilities