ZeroHour

CVE-2020-25078

KEVmoderate

Unauthenticated Admin Password Disclosure in D-Link DCS-2530L/2670L Cameras

CISA: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

CVSS 3.1
7.5 high
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2020-25078 is an information-disclosure flaw in the unauthenticated /config/getuser endpoint of D-Link DCS-2530L and DCS-2670L network cameras, which allows a remote, unauthenticated attacker to retrieve the device's administrator password. It is triggered simply by sending a crafted request to that HTTP endpoint over the network, with no login or user interaction required. An attacker who obtains the administrator password can log into the camera's web interface to view footage, change settings, or pivot further into the network. Owners of a DCS-2530L running firmware before 1.06.01 Hotfix or a DCS-2670L running firmware through 2.02 with the camera's web interface reachable are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid active-exploitation evidence (with FBI/CISA alerts on HiatusRAT campaigns targeting webcams and DVRs), and its EPSS score of 97.9% indicates a very high near-term exploitation probability.

What to do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and for DCS-2670L apply the latest vendor hotfix release newer than 2.02 (check D-Link's support page, as the exact fixed version is not specified in this data). Do not expose the camera web interface directly to the internet (remove port forwards/UPnP mappings or restrict access via firewall), and check device logs or perimeter traffic for unauthenticated requests to /config/getuser. Because these devices are end-of-life, plan replacement if current mitigations or firmware updates are unavailable, consistent with BOD 22-01 guidance.

Affected
D-Link DCS-2530L camera firmwarebefore 1.06.01 Hotfix
D-Link DCS-2670L camera firmwarethrough 2.02 (fixed version not specified in source data)
D-Link DCS-4603 firmware
D-Link DCS-4622 firmware
D-Link DCS-4701E firmware
D-Link DCS-4703E firmware
D-Link DCS-4705E firmware
D-Link DCS-4802E firmware
D-Link DCS-P703 firmware
Estimated exposure
moderatelikely on the order of tens of thousands of internet-exposed camera units (estimate; no authoritative counts in source data) — These are discontinued consumer Wi-Fi cameras that owners commonly expose directly to the internet via port forwarding or cloud access, so an order-of-magnitude estimate of tens of thousands of exposed devices is inferred from typical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

CISA Known Exploited Vulnerability
Affected
D-Link DCS-2530L and DCS-2670L Devices
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dcs-4603 firmware, dcs-4622 firmware, dcs-4701e firmware, dcs-4703e firmware, dcs-4705e firmware, dcs-4802e firmware, dcs-p703 firmware, dcs-2530l firmware, dcs-2670l firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news