Skip to content
COOEY

FAIL › dossier

DCS-2530L and DCS-2670L Devices

PRODUCT

· dossier confidence 20%

D-Link's DCS-2530L and DCS-2670L surveillance cameras suffered high-severity RCE and command injection vulnerabilities that were left unpatched and actively exploited, revealing a pattern of delayed firmware updates and poor vulnerability management in its edge-device product line.

PROFILE
Categorynetworking/securityWhat they doD-Link manufactures networking and security devices, including the DCS-2530L and DCS-2670L surveillance cameras. Websitehttps://www.dlink.com ↗
SECURITY POSTURE

D-Link has a poor security posture, evidenced by multiple high-severity RCE and command injection vulnerabilities in its DCS-2530L and DCS-2670L devices that remained unpatched and were actively exploited in the wild.

Notable failures
  • CVE-2020-25078: Remote admin password disclosure
  • CVE-2020-25079: Unpatched command injection exploited in the wild
Patterns: repeated unpatched edge-device RCEs; delayed firmware updates for surveillance hardware
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-08-05 CVE-2020-25078 high D-Link's DCS-2530L and DCS-2670L devices exposed to remote admin password disclosure.
2025-08-05 CVE-2020-25079 high D-Link's DCS-2530L and DCS-2670L devices had unpatched command injection vulnerabilities actively exploited in the wild.
Open questions: D-Link's current patch management process for edge devices · Whether D-Link has implemented any compensating controls for affected devices
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 04:03:56.738208+00:00