PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-25078 Scanner

Detects 'Credential Disclosure' vulnerability in D-Link DCS-2530L and DCS-2670L affects v. DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-25078
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 10, 2026View on NVD →
Detail

D-Link DCS-2530L and DCS-2670L are wireless indoor/outdoor surveillance cameras designed to enhance the security of commercial and residential properties. These devices feature 180-degree wide-angle views, Wi-Fi connectivity, motion detection, and high-quality video resolution for optimal coverage and surveillance.

Recently, a vulnerability has been detected in these devices, indicating that the unauthenticated /config/getuser endpoint can allow remote administrator password disclosure. This vulnerability, labeled CVE-2020-25078, puts the privacy and security of the surveillance camera users at risk, as it can be exploited by unauthorized individuals to gain access to confidential information.

If exploited, this vulnerability can allow hackers to discover the remote administrator password and access the surveillance camera without any authentication. Hackers can gain full control of the device, access live footage, tamper with the settings, and even turn off the device's security features. This can lead to the leakage of sensitive information, illegal surveillance, and unauthorized access to the property.

Thanks to the professional features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets. Through the platform, users can identify vulnerabilities within their assets, develop an efficient remediation plan, and improve their overall security posture, ensuring a safe digital environment.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following steps can be taken:

  • Upgrade the firmware of the D-Link DCS-2530L and DCS-2670L devices to the latest version, which includes a patch to fix the vulnerability.
  • Enable multi-factor authentication, which adds an extra layer of security to the login process.
  • Change the default login credentials to a unique and strong password that is not easily guessable.
  • Disable or block the /config/getuser endpoint if not needed.
  • Continuous monitoring of the surveillance camera footage and activity logs to detect any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.