CVE-2020-25078
Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
Vulnerability Description
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
Affected Platforms (CPE)
💻
Dlink
Dcs 4603 Firmware
< 1.04.02💻
Dlink
Dcs 4622 Firmware
< 2.01.10💻
Dlink
Dcs 4701e Firmware
< 2.03.01💻
Dlink
Dcs 4703e Firmware
< 1.03.04💻
Dlink
Dcs 4705e Firmware
< 1.03.02💻
Dlink
Dcs 4802e Firmware
< 2.01.01💻
Dlink
Dcs P703 Firmware
All versions💻
Dlink
Dcs 2530l Firmware
<= 1.05.05💻
Dlink
