An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
No PoCs from references.
- https://github.com/404notf0und/CVE-Flow
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/CryptoGenNepal/CVE-KEV-RSS
- https://github.com/DevGreick/devgreick
- https://github.com/fishykz/2530L-analyze
- https://github.com/packetinside/CISA_BOT
- https://github.com/ums91/CISA_BOT