CVE-2020-25078
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
- Affected products
- D-Link Dcs-2530L, D-Link Dcs-2670L
- Dlink dcs-4603 Firmware
- < 1.04.02
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 97.9% (100th percentile)
- NVD status
- Analyzed
- Published
- 2020-09-02
CVE-2020-25078 at NVD
7 known exploits for CVE-2020-25078
Proof-of-concept code and exploit modules indexed by Sploitus