LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-25078: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 5, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 26, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-25078 to its Known Exploited Vulnerabilities catalog on Aug 5, 2025, with a federal patch deadline of Aug 26, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or…

CVE-2020-25078 is an unspecified vulnerability affecting D-Link DCS-2530L and DCS-2670L devices that can allow remote disclosure of the administrator password. These products are network-connected IP cameras commonly used for surveillance. The issue matters because successful exploitation can hand an attacker administrative control of the device, potentially exposing live video feeds, stored footage, or the camera as a foothold into the broader network. Impacted units may already be end-of-life or end-of-service, leaving them without ongoing vendor support.

IT and security teams should treat any internet-reachable or poorly segmented instance of these models as high priority for review, given the direct path to credential theft and device takeover.

How it works

The vulnerability class involves remote administrator password disclosure on the named D-Link camera models. An unauthenticated or low-privilege remote attacker can trigger the flaw to obtain the administrative credentials. Once those credentials are known, the attacker can log in with full privileges, reconfigure the device, view or exfiltrate media streams, or use the camera as a pivot point. Because the exact technical details and CWE are not specified in the available record, defenders must treat the issue as a remote credential-exposure weakness typical of embedded network devices and confirm precise attack mechanics against the vendor advisory. No public ransomware association has been documented for this CVE.

Am I affected? How to find it in your systems

These devices are D-Link consumer and small-business IP cameras that typically appear on local networks, often with web management interfaces or cloud-connectivity features. Inventory steps include:

Telemetry signs of exploitation can include unexpected administrative logins from external or unusual internal addresses, sudden configuration changes, or outbound connections that do not match normal camera behavior. Correlate these with authentication and system logs on the cameras themselves or on any central video-management platform.

How to remediate

Follow the CISA-required action: apply mitigations exactly as instructed by the vendor, or discontinue use of the product if mitigations are unavailable. Because the devices may be end-of-life or end-of-service, the practical long-term remediation for many organizations is replacement with supported hardware. After any vendor-supplied update or configuration change is applied, re-inventory the devices to confirm the change took effect and that administrative credentials have been rotated. Document the action for compliance and future audits.

If you can't patch immediately

Until a permanent fix or replacement is in place, reduce exposure with the following compensating controls:

These steps do not eliminate the vulnerability but shrink the attack surface until the devices can be updated or retired.

If your data may have been exposed

Actively exploited remote password-disclosure flaws on network devices frequently lead to unauthorized access and data exposure. If these cameras were reachable and unpatched, assume administrative credentials and any media they store or stream may have been compromised. Rotate all related passwords, review video archives for unauthorized access, and examine network logs for lateral movement. As a quick additional check, individuals can run a free exposure scan of their email addresses against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DCS-2530L and DCS-2670L Devices
Added to CISA KEVAug 5, 2025
Federal patch deadlineAug 26, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities