CVE-2020-25078

9.5 CISA KEV

D-Link · DCS-2530L and DCS-2670L

An unauthenticated vulnerability in the D-Link DCS-2530L and DCS-2670L web interface allows remote attackers to disclose administrator credentials via the /config/getuser endpoint.

Executive summary

This critical vulnerability allows unauthenticated remote attackers to steal administrator credentials from D-Link IP cameras, and it is currently being actively exploited in the wild.

Vulnerability

This is an authentication bypass vulnerability within the web management interface of the affected cameras. An unauthenticated attacker can interact with the /config/getuser endpoint to retrieve administrator credentials in plaintext.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it grants attackers full administrative control over the affected camera devices. With a CVSS score of 9.5, this flaw facilitates unauthorized access, potential data exfiltration, and the integration of these devices into botnets, such as the HiatusRAT campaign. Such compromise can lead to significant reputational damage and the loss of physical site security monitoring.

Remediation

Immediate Action: Update the DCS-2530L firmware to the 1.06.01 Hotfix version or higher, and apply the corresponding security patch for the DCS-2670L as provided by the vendor.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the /config/getuser endpoint and inspect device logs for unexpected administrative login events.

Compensating Controls: Immediately isolate affected devices from the public internet using a firewall or VPN, and restrict access to the web management interface to trusted internal management subnets.

Exploitation status

Public Exploit Available: Yes, multiple proof-of-concept repositories are publicly available on GitHub.

Analyst recommendation

Given the critical severity of this vulnerability and the confirmed reports of active exploitation by malicious actors, organizations must prioritize the immediate patching or isolation of all affected D-Link camera devices. Failure to address this flaw leaves systems exposed to complete administrative takeover, and standard security practices dictate that these devices should not remain exposed to the public internet under any circumstances.

More D-Link CVEs

Sources