9
CVSSv2

CVE-2020-25079

Published: 02/09/2020 Updated: 21/07/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists on D-Link DCS-2530L prior to 1.06.01 Hotfix and DCS-2670L up to and including 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dcs-2530l_firmware

dlink dcs-2670l_firmware

Github Repositories

yk2eR0@HATLAB 官网公告 Authenticated Command Injection and Unauthenticated Credential Disclosure 影响范围 DCS-2530L v10505 & older DCS-2670L v202 & older 测试环境 设备厂商:D-Link 设备型号:D-Link DCS-2530L 设备版本:104 关键程序提取 由于公布的两个漏洞CVE-2020-25079 + CVE-2020-2507刚好一个敏感信息