Skip to content
COOEY

EXPOSURES › CVE-2020-25078

CVE-2020-25078

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-08-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25078 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

D-Link's DCS-2530L and DCS-2670L devices exposed to remote admin password disclosure.

D-Link's DCS-2530L and DCS-2670L networking devices had an unspecified vulnerability that allowed for remote administrator password disclosure, posing a significant risk to organizations adhering to CMMC/NIST 800-171 standards. Users were advised to cease using these end-of-life and end-of-service products immediately.

Shame score — Repeated history of RCE vulnerabilities in D-Link consumer firmware, including critical remote code execution issues in other models like DIR-816A2 and DIR-823G, indicating a systemic security deficiency.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.