EXPOSURES › CVE-2020-25078
CVE-2020-25078
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link's DCS-2530L and DCS-2670L devices exposed to remote admin password disclosure.
D-Link's DCS-2530L and DCS-2670L networking devices had an unspecified vulnerability that allowed for remote administrator password disclosure, posing a significant risk to organizations adhering to CMMC/NIST 800-171 standards. Users were advised to cease using these end-of-life and end-of-service products immediately.
Shame score — Repeated history of RCE vulnerabilities in D-Link consumer firmware, including critical remote code execution issues in other models like DIR-816A2 and DIR-823G, indicating a systemic security deficiency.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.