CVE-2020-25078
KEVHIGH 7.5EPSS 97.9%
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 97.90% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-08-05
- Nuclei
- high
- Published
- 2020-09-02
- Updated
- 2025-10-21
Proof-of-concept exploits (3)
- MzzdToT/CVE-2020-250784★ · 2021-03-30
- antx-code/pocx17★ · 2023-07-04
- chinaYozz/CVE-2020-250780★ · 2021-10-15
Nuclei templates (1)
Exploit collections (3)
- chaitin/xray/blob/master/pocs/dlink-cve-2020-25078-account-disclosure.yml
- tzwlhack/Vulnerability/blob/main/D-Link%20DCS%E7%B3%BB%E5%88%97%E7%9B%91%E6%8E%A7%20%E8%B…
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2020/CVE-2020-25078.yaml