CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation Evidence
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-25079 +1 in the same advisory: …25078 | Authenticated Command Injection in D-Link DCS-2530L and DCS-2670L Cameras D-Link DCS-2530L and DCS-2670L IP camera firmware contains an authenticated command injection flaw (CWE-77) in the cgi-bin/ddns_enc.cgi endpoint, which handles dynamic DNS (DDNS) configuration. An attacker with valid credentials for the camera's web interface (default or weak passwords are common on consumer cameras) can submit crafted input through this endpoint to execute arbitrary operating-system commands on the device; the CVSS 3.1 score of 8.8 reflects network reachability, low privilege required, no user interaction, and high confidentiality, integrity, and availability impact. Successful compromise gives the attacker control of the camera, access to its video feed, and a potential foothold for pivoting into the network the camera sits on. The affected population is DCS-2530L units on firmware before 1.06.01 Hotfix and DCS-2670L units on firmware through 2.02, typically deployed in homes and small-business settings. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid evidence of active exploitation, and EPSS assigns it a 52.7% probability of exploitation within 30 days (99th percentile). Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and DCS-2670L cameras to a post-2.02 firmware/hotfix per D-Link's advisory; since these are older consumer models that may no longer receive updates, replace or retire units that cannot be patched. Because exploitation requires valid credentials, enforce strong non-default passwords, remove internet-facing port forwarding/UPnP exposure of the cameras' web interfaces, and restrict management access to trusted networks; U.S. federal agencies should follow the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable. Given the KEV listing, check exposed units for signs of compromise such as modified settings or unexpected outbound connections. | 8.8 group max | 56% | KEV PoC |
| moderateplausibly tens of thousands of deployed units worldwide, with likely only low thousands directly internet-exposed (estimate) |
Full article298 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 06, 2025Vulnerability / Firmware Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three old security flaws impacting D-Link Wi-Fi cameras and video recorders to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.
The high-severity vulnerabilities, which are from 2020 and 2022, are listed below -
- CVE-2020-25078 (CVSS score: 7.5) - An unspecified vulnerability in D-Link DCS-2530L and DCS-2670L devices that could allow for remote administrator password disclosure
- CVE-2020-25079 (CVSS score: 8.8) - An authenticated command injection vulnerability in the cgi-bin/ddns_enc.cgi component affecting D-Link DCS-2530L and DCS-2670L devices
- CVE-2020-40799 (CVSS score: 8.8) - A download of code without an integrity check vulnerability in D-Link DNR-322L that could allow an authenticated attacker to execute operating system-level commands on the device
There are currently no details on how these shortcomings are being exploited in the wild, although a December 2024 advisory from the U.S. Federal Bureau of Investigation (FBI) warned of HiatusRAT campaigns actively scanning web cameras that are vulnerable to CVE-2020-25078.
It's worth noting that CVE-2020-40799 remains unpatched due to the affected model reaching end-of-life (EoL) status as of November 2021. Users still relying on DNR-322L are advised to discontinue and replace them. Fixes for the other two flaws were released by D-Link in 2020.
In light of active exploitation, it's essential that Federal Civilian Executive Branch (FCEB) agencies carry out the necessary mitigation steps by August 26, 2025, to secure their networks.
(The story was updated after publication to emphasize that the issues affect D-Link Wi-Fi cameras and video recorders and not routers as previously stated. The error is regretted.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/08/cisa-adds-3-d-link-router-flaws-to-kev.html