CVE-2020-25078

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/09/2020
Last modified:
07/11/2025

Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:* 1.04.02 (excluding)
cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:* 2.01.10 (excluding)
cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:* 2.03.01 (excluding)
cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:* 1.03.04 (excluding)
cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:* 1.03.02 (excluding)
cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:* 2.01.01 (excluding)
cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:* 1.05.05 (including)