Vulnerability Description
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dcs-4603 Firmware | < 1.04.02 |
| Dlink | Dcs-4603 | - |
| Dlink | Dcs-4622 Firmware | < 2.01.10 |
| Dlink | Dcs-4622 | - |
| Dlink | Dcs-4701E Firmware | < 2.03.01 |
| Dlink | Dcs-4701E | - |
| Dlink | Dcs-4703E Firmware | < 1.03.04 |
| Dlink | Dcs-4703E | - |
| Dlink | Dcs-4705E Firmware | < 1.03.02 |
| Dlink | Dcs-4705E | - |
| Dlink | Dcs-4802E Firmware | < 2.01.01 |
| Dlink | Dcs-4802E | - |
| Dlink | Dcs-P703 Firmware | All versions |
| Dlink | Dcs-P703 | - |
| Dlink | Dcs-2530L Firmware | <= 1.05.05 |
| Dlink | Dcs-2530L | - |
| Dlink | Dcs-2670L Firmware | < 2.03.00 |
| Dlink | Dcs-2670L | - |
References
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://twitter.com/Dogonsecurity/status/1273251236167516161Broken LinkThird Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP1PatchVendor Advisory
- https://twitter.com/Dogonsecurity/status/1273251236167516161Broken LinkThird Party Advisory
- https://support.dlink.com/productinfo.aspx?m=DCS-2530LProduct
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-US Government Resource
FAQ
What is CVE-2020-25078?
CVE-2020-25078 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
How severe is CVE-2020-25078?
CVE-2020-25078 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25078?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dcs-4603 Firmware, Dlink Dcs-4603, Dlink Dcs-4622 Firmware, Dlink Dcs-4622, Dlink Dcs-4701E Firmware.