← Back to browse · API

CVE-2020-25078

Severity
HIGH
CVSS
7.5
EPSS
0.97711
Risk score
59.2
CISA KEV
Yes
PoC
No
Published
2020-09-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-17770, GHSA-858V-PCFH-P8XG
Products
D-Link:DCS-2530L and DCS-2670L Devices, n/a:n/a n/a
Sources
cisa.gov CVE-2020-25078
euvd EUVD-2020-17770

Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

References