CVE-2020-25079
KEV PoC moderateAuthenticated Command Injection in D-Link DCS-2530L and DCS-2670L Cameras
CISA: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L IP camera firmware contains an authenticated command injection flaw (CWE-77) in the cgi-bin/ddns_enc.cgi endpoint, which handles dynamic DNS (DDNS) configuration. An attacker with valid credentials for the camera's web interface (default or weak passwords are common on consumer cameras) can submit crafted input through this endpoint to execute arbitrary operating-system commands on the device; the CVSS 3.1 score of 8.8 reflects network reachability, low privilege required, no user interaction, and high confidentiality, integrity, and availability impact. Successful compromise gives the attacker control of the camera, access to its video feed, and a potential foothold for pivoting into the network the camera sits on. The affected population is DCS-2530L units on firmware before 1.06.01 Hotfix and DCS-2670L units on firmware through 2.02, typically deployed in homes and small-business settings. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid evidence of active exploitation, and EPSS assigns it a 52.7% probability of exploitation within 30 days (99th percentile).
What to do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and DCS-2670L cameras to a post-2.02 firmware/hotfix per D-Link's advisory; since these are older consumer models that may no longer receive updates, replace or retire units that cannot be patched. Because exploitation requires valid credentials, enforce strong non-default passwords, remove internet-facing port forwarding/UPnP exposure of the cameras' web interfaces, and restrict management access to trusted networks; U.S. federal agencies should follow the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable. Given the KEV listing, check exposed units for signs of compromise such as modified settings or unexpected outbound connections.
| D-Link DCS-2530L firmware | before 1.06.01 Hotfix |
| D-Link DCS-2670L firmware | through 2.02 (fix requires firmware beyond 2.02 per vendor) |
| D-Link DCS-4703E firmware | — |
| D-Link DCS-4705E firmware | — |
| D-Link DCS-4802E firmware | — |
| D-Link DCS-P703 firmware | — |
| D-Link DCS-4603 firmware | — |
| D-Link DCS-4622 firmware | — |
| D-Link DCS-4701E firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
- Affected
- D-Link DCS-2530L and DCS-2670L Devices
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dcs-4703e firmware, dcs-4705e firmware, dcs-4802e firmware, dcs-p703 firmware, dcs-4603 firmware, dcs-4622 firmware, dcs-4701e firmware, dcs-2530l firmware, dcs-2670l firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H