An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
| Software | From | Fixed in |
|---|---|---|
| dlink / dcs-2530l_firmware | - | 1.05.05.x |
| dlink / dcs-4603_firmware | - | 1.04.02 |
| dlink / dcs-4622_firmware | - | 2.01.10 |
| dlink / dcs-4701e_firmware | - | 2.03.01 |
| dlink / dcs-4703e_firmware | - | 1.03.04 |
| dlink / dcs-4705e_firmware | - | 1.03.02 |
| dlink / dcs-4802e_firmware | - | 2.01.01 |
| dlink / dcs-p703_firmware | - | - |
| dlink / dcs-2670l_firmware | - | 2.03.00 |