An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
References
| Link | Resource |
|---|---|
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | Patch Vendor Advisory |
| https://twitter.com/Dogonsecurity/status/1271265152118259712 | Exploit Third Party Advisory Broken Link |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 | Patch Vendor Advisory |
| https://twitter.com/Dogonsecurity/status/1271265152118259712 | Exploit Third Party Advisory Broken Link |
| https://support.dlink.com/productinfo.aspx?m=DCS-2530L | Product |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
History
07 Nov 2025, 22:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://twitter.com/Dogonsecurity/status/1271265152118259712 - Exploit, Third Party Advisory, Broken Link | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-25079 - US Government Resource |
22 Oct 2025, 00:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Aug 2025, 20:42
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.dlink.com/productinfo.aspx?m=DCS-2530L - Product | |
| First Time |
Dlink dcs-4622 Firmware
Dlink dcs-4603 Dlink dcs-p703 Dlink dcs-4701e Dlink dcs-4802e Firmware Dlink dcs-4705e Firmware Dlink dcs-4622 Dlink dcs-4802e Dlink dcs-4703e Dlink dcs-p703 Firmware Dlink dcs-4705e Dlink dcs-4703e Firmware Dlink dcs-4701e Firmware Dlink dcs-4603 Firmware |
|
| CPE | cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:* |
05 Aug 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 05:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180 - Patch, Vendor Advisory | |
| References | () https://twitter.com/Dogonsecurity/status/1271265152118259712 - Exploit, Third Party Advisory |
Information
Published : 2020-09-02 16:15
Updated : 2025-11-07 22:02
NVD link : CVE-2020-25079
Mitre link : CVE-2020-25079
CVE.ORG link : CVE-2020-25079
JSON object : View
Products Affected
dlink
- dcs-p703
- dcs-4705e
- dcs-4703e_firmware
- dcs-4603_firmware
- dcs-2670l
- dcs-4802e
- dcs-4701e_firmware
- dcs-4603
- dcs-4705e_firmware
- dcs-4622
- dcs-4701e
- dcs-2530l
- dcs-2670l_firmware
- dcs-4622_firmware
- dcs-p703_firmware
- dcs-4703e
- dcs-4802e_firmware
- dcs-2530l_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
