CVE-2020-25079

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-2530l:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dlink:dcs-2670l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-2670l:-:*:*:*:*:*:*:*

History

07 Nov 2025, 22:02

Type Values Removed Values Added
References () https://twitter.com/Dogonsecurity/status/1271265152118259712 - Exploit, Third Party Advisory () https://twitter.com/Dogonsecurity/status/1271265152118259712 - Exploit, Third Party Advisory, Broken Link
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079 - US Government Resource

Information

Published : 2020-09-02 16:15

Updated : 2025-11-07 22:02


NVD link : CVE-2020-25079

Mitre link : CVE-2020-25079

CVE.ORG link : CVE-2020-25079


JSON object : View

Products Affected

dlink

  • dcs-2670l_firmware
  • dcs-4603_firmware
  • dcs-4802e_firmware
  • dcs-p703_firmware
  • dcs-4802e
  • dcs-4603
  • dcs-4701e_firmware
  • dcs-2530l_firmware
  • dcs-4703e_firmware
  • dcs-4703e
  • dcs-4622
  • dcs-2670l
  • dcs-p703
  • dcs-4701e
  • dcs-2530l
  • dcs-4705e_firmware
  • dcs-4622_firmware
  • dcs-4705e
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')