ZeroHour

CVE-2020-25079

KEV PoC moderate

Authenticated Command Injection in D-Link DCS-2530L and DCS-2670L Cameras

CISA: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
56%p99
Published
()
KEV added
AI analysis

D-Link DCS-2530L and DCS-2670L IP camera firmware contains an authenticated command injection flaw (CWE-77) in the cgi-bin/ddns_enc.cgi endpoint, which handles dynamic DNS (DDNS) configuration. An attacker with valid credentials for the camera's web interface (default or weak passwords are common on consumer cameras) can submit crafted input through this endpoint to execute arbitrary operating-system commands on the device; the CVSS 3.1 score of 8.8 reflects network reachability, low privilege required, no user interaction, and high confidentiality, integrity, and availability impact. Successful compromise gives the attacker control of the camera, access to its video feed, and a potential foothold for pivoting into the network the camera sits on. The affected population is DCS-2530L units on firmware before 1.06.01 Hotfix and DCS-2670L units on firmware through 2.02, typically deployed in homes and small-business settings. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid evidence of active exploitation, and EPSS assigns it a 52.7% probability of exploitation within 30 days (99th percentile).

What to do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and DCS-2670L cameras to a post-2.02 firmware/hotfix per D-Link's advisory; since these are older consumer models that may no longer receive updates, replace or retire units that cannot be patched. Because exploitation requires valid credentials, enforce strong non-default passwords, remove internet-facing port forwarding/UPnP exposure of the cameras' web interfaces, and restrict management access to trusted networks; U.S. federal agencies should follow the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable. Given the KEV listing, check exposed units for signs of compromise such as modified settings or unexpected outbound connections.

Affected
D-Link DCS-2530L firmwarebefore 1.06.01 Hotfix
D-Link DCS-2670L firmwarethrough 2.02 (fix requires firmware beyond 2.02 per vendor)
D-Link DCS-4703E firmware
D-Link DCS-4705E firmware
D-Link DCS-4802E firmware
D-Link DCS-P703 firmware
D-Link DCS-4603 firmware
D-Link DCS-4622 firmware
D-Link DCS-4701E firmware
Estimated exposure
moderateplausibly tens of thousands of deployed units worldwide, with likely only low thousands directly internet-exposed (estimate) — No authoritative install or exposure counts are in the provided data; the estimate is based on typical install bases for discontinued D-Link consumer camera SKUs (tens of thousands of units) and the common deployment pattern in which such…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

CISA Known Exploited Vulnerability
Affected
D-Link DCS-2530L and DCS-2670L Devices
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dcs-4703e firmware, dcs-4705e firmware, dcs-4802e firmware, dcs-p703 firmware, dcs-4603 firmware, dcs-4622 firmware, dcs-4701e firmware, dcs-2530l firmware, dcs-2670l firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news