High severity7.5CISA KEVNVD Advisory· Published Sep 2, 2020· Updated Jun 17, 2026
CVE-2020-25078
CVE-2020-25078
Description
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*
- D-Link/DCS-2530Ldescription
Patches
Vulnerability mechanics
References
4- supportannouncement.us.dlink.com/announcement/publication.aspxnvdPatchVendor Advisory
- twitter.com/Dogonsecurity/status/1273251236167516161nvdBroken LinkThird Party Advisory
- support.dlink.com/productinfo.aspxnvdProduct
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.