« Back to list

Dlink

Dlink Dcs-4705e Firmware: vulnerabilities and CVEs

Dlink Dcs-4705e Firmware has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 2 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-25079High (8.8)54%⚠ Active exploitationSep 2, 2020
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
CVE-2020-25078High (7.5)98%⚠ Active exploitationSep 2, 2020
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-25079High (8.8)54%⚠ Active exploitationSep 2, 2020
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
CVE-2020-25078High (7.5)98%⚠ Active exploitationSep 2, 2020
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.001 PowerShell1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Dlink