EXPOSURES › CVE-2020-25079
CVE-2020-25079
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link's DCS-2530L and DCS-2670L devices had unpatched command injection vulnerabilities actively exploited in the wild.
D-Link's DCS-2530L and DCS-2670L devices, which may be end-of-life or end-of-service, have command injection vulnerabilities that have been actively exploited. Users should cease using these products immediately.
Shame score — Repeated history of critical remote code execution vulnerabilities in D-Link consumer firmware, including multiple command injection flaws discovered between 2021 and 2024, indicating a critically poor security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.