9

CVE-2020-25079

Warning
Exploit

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

Data is provided by the National Vulnerability Database (NVD)
DlinkDcs-4703e Firmware Version < 1.03.04
   DlinkDcs-4703e Version-
DlinkDcs-4705e Firmware Version < 1.03.02
   DlinkDcs-4705e Version-
DlinkDcs-4802e Firmware Version < 2.01.01
   DlinkDcs-4802e Version-
DlinkDcs-p703 Firmware
   DlinkDcs-p703 Version-
DlinkDcs-4603 Firmware Version < 1.04.02
   DlinkDcs-4603 Version-
DlinkDcs-4622 Firmware Version < 2.01.10
   DlinkDcs-4622 Version-
DlinkDcs-4701e Firmware Version < 2.03.01
   DlinkDcs-4701e Version-
DlinkDcs-2530l Firmware Version <= 1.05.05
   DlinkDcs-2530l Version-
DlinkDcs-2670l Firmware Version < 2.03.00
   DlinkDcs-2670l Version-

05.08.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Description

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 42.69% 0.974
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.