Skip to content
COOEY

EXPOSURES › CVE-2020-25079

CVE-2020-25079

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-08-05 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25079 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

D-Link's DCS-2530L and DCS-2670L devices had unpatched command injection vulnerabilities actively exploited in the wild.

D-Link's DCS-2530L and DCS-2670L devices, which may be end-of-life or end-of-service, have command injection vulnerabilities that have been actively exploited. Users should cease using these products immediately.

Shame score — Repeated history of critical remote code execution vulnerabilities in D-Link consumer firmware, including multiple command injection flaws discovered between 2021 and 2024, indicating a critically poor security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.