Junglewise Threat Intelligence

CVE-2020-25078: D-Link DCS Cameras administrator password disclosure in /config/getuser

CVE-2020-25078 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-08-05

Vendors: D-Link.

Executive brief

Multiple D-Link network cameras contain a security flaw that allows unauthorized individuals to remotely view the administrator's password. This could allow an attacker to take full control of the camera, view private video feeds, or use the device as a foothold to attack other systems on the network. Because many of these devices are older or at the end of their service life, users are strongly advised to update their firmware or replace the hardware.

Technical details

An information disclosure vulnerability exists in the web management interface of several D-Link DCS-series IP cameras. The root cause is an insecurely exposed endpoint, '/config/getuser', which does not require authentication and returns sensitive configuration data, including the administrator password. A remote attacker with network access to the device's web interface can exploit this by sending a simple HTTP request to the vulnerable endpoint. Successful exploitation grants the attacker full administrative credentials, leading to complete device compromise. This vulnerability has been observed in active exploitation in the wild.

Affected products

  • D-Link DCS-2530L firmware before 1.06.01 Hotfix
  • D-Link DCS-2670L firmware up to and including 2.02
  • D-Link DCS-4603 firmware before 1.04.02
  • D-Link DCS-4622 firmware before 2.01.10
  • D-Link DCS-4701E firmware before 2.03.01
  • D-Link DCS-4703E firmware before 1.03.04
  • D-Link DCS-4705E firmware before 1.03.02
  • D-Link DCS-4802E firmware before 2.01.01

Timeline

  • 2020-06-17: disclosed: Initial public report via social media/third party
  • 2025-08-05: kev added: CISA added to Known Exploited Vulnerabilities catalog
  • 2025-08-05: advisory: NVD publication date

Related threats