ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds D-Link cameras and Network Video Recorder flaws to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2020-25078CVE-2020-25079CVE-2022-40799

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-25079
+1 in the same advisory: …25078
Authenticated Command Injection in D-Link DCS-2530L and DCS-2670L Cameras

D-Link DCS-2530L and DCS-2670L IP camera firmware contains an authenticated command injection flaw (CWE-77) in the cgi-bin/ddns_enc.cgi endpoint, which handles dynamic DNS (DDNS) configuration. An attacker with valid credentials for the camera's web interface (default or weak passwords are common on consumer cameras) can submit crafted input through this endpoint to execute arbitrary operating-system commands on the device; the CVSS 3.1 score of 8.8 reflects network reachability, low privilege required, no user interaction, and high confidentiality, integrity, and availability impact. Successful compromise gives the attacker control of the camera, access to its video feed, and a potential foothold for pivoting into the network the camera sits on. The affected population is DCS-2530L units on firmware before 1.06.01 Hotfix and DCS-2670L units on firmware through 2.02, typically deployed in homes and small-business settings. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid evidence of active exploitation, and EPSS assigns it a 52.7% probability of exploitation within 30 days (99th percentile).

Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and DCS-2670L cameras to a post-2.02 firmware/hotfix per D-Link's advisory; since these are older consumer models that may no longer receive updates, replace or retire units that cannot be patched. Because exploitation requires valid credentials, enforce strong non-default passwords, remove internet-facing port forwarding/UPnP exposure of the cameras' web interfaces, and restrict management access to trusted networks; U.S. federal agencies should follow the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable. Given the KEV listing, check exposed units for signs of compromise such as modified settings or unexpected outbound connections.

8.8
group max
56% KEV PoC
  • D-Link DCS-2530L firmware before 1.06.01 Hotfix
  • D-Link DCS-2670L firmware through 2.02 (fix requires firmware beyond 2.02 per vendor)
  • D-Link DCS-4703E firmware
  • +6 more
moderateplausibly tens of thousands of deployed units worldwide, with likely only low thousands directly internet-exposed (estimate)
CVE-2022-40799
Unsigned Code Download Enables OS Command Execution in D-Link DNR-322L NVR

CVE-2022-40799 is a download-of-code-without-integrity-check flaw (CWE-494) in the D-Link DNR-322L network video recorder, which accepts and runs downloaded code without verifying it is authentic and unmodified. An attacker who already holds valid credentials on the device can trigger download and execution of unsigned code, gaining the ability to issue operating-system-level commands on the NVR. Successful exploitation yields control of the recorder, its stored camera footage, and a foothold for further attacks on the surveillance network. Only D-Link DNR-322L deployments are affected, and the product is end-of-life/end-of-service, so owners should expect limited or no vendor remediation and are advised to discontinue use. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2025-08-05, EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), and no public proof-of-concept is known.

Do: Inventory your environment for DNR-322L recorders and, per CISA's required action, apply any mitigations D-Link has published or retire the device, since the product is EoL/EoS and the vendor recommends discontinuing use. If the recorder must stay in service, keep its management interface off the public internet behind a firewall and monitor for signs of command execution; federal agencies must remediate or discontinue use in line with BOD 22-01 deadlines.

8.834% KEV PoC
  • D-Link DNR-322L Network Video Recorder
moderatelikely low tens of thousands of surviving units worldwide, of which only a few thousand are internet-exposed
Full article229 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds D-Link cameras and Network Video Recorder flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2020-25078 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability. A vulnerability in D-Link DCS-2530L (pre-1.06.01 Hotfix) and DCS-2670L (up to 2.02) allows remote attackers to access the admin password via an unauthenticated endpoint.
  • CVE-2020-25079 D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability. D-Link DCS-2530L (pre-1.06.01 Hotfix) and DCS-2670L (up to 2.02) devices have a flaw in cgi-bin/ddns_enc.cgi that allows authenticated command injection.
  • CVE-2022-40799 D-Link DNR-322L Download of Code Without Integrity Check Vulnerability. A data integrity flaw in the “Backup Config” feature of D-Link DNR-322L (≤ 2.60B15) lets authenticated attackers run OS-level commands on the device.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by August 26, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180833/security/u-s-cisa-adds-d-link-cameras-and-network-video-recorder-flaws-to-its-known-exploited-vulnerabilities-catalog.html