CVE-2020-25079Active Exploitation(dlink / dcs-2530l)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dlink dcs-2530l systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dcs-2530l
  • dcs-2530l_firmware
  • dcs-2670l
  • dcs-2670l_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
dcs-2530ldcs-2530l_firmwaredcs-2670ldcs-2670l_firmwaredcs-4603dcs-4603_firmwaredcs-4622dcs-4622_firmwaredcs-4701edcs-4701e_firmware

1 version affected across 18 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-16: 1Active Exploitation · 2026-08-16: 1Technical Details · 2026-08-16: 108-16
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PJ@Npj8448
    Active Exploitation

    🚨 Active exploitation of high-severity vulnerabilities like CVE-2019-9875 and CVE-2020-25079 is on the rise, allowing for remote code execution and deserialization of untrusted data #ThreatIntel #CyberSecurity #CVE https://pranithjain.qzz.io/threatintel/telegram?tab=firehose

    Post summary

    The tweet alerts that CVE-2019-9875 and CVE-2020-25079 are increasingly being exploited for remote code execution and deserialization attacks, with no patches or mitigation details provided.

    0000047
    63 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdcs-2530l---
OSdlinkdcs-2530l_firmware---
HWdlinkdcs-2670l---
OSdlinkdcs-2670l_firmware---
HWdlinkdcs-4603---
OSdlinkdcs-4603_firmware---
HWdlinkdcs-4622---
OSdlinkdcs-4622_firmware---
HWdlinkdcs-4701e---
OSdlinkdcs-4701e_firmware---
HWdlinkdcs-4703e---
OSdlinkdcs-4703e_firmware---
HWdlinkdcs-4705e---
OSdlinkdcs-4705e_firmware---
HWdlinkdcs-4802e---
OSdlinkdcs-4802e_firmware---
HWdlinkdcs-p703---
OSdlinkdcs-p703_firmware---

Explore more