Evidence dossier

CVE-2020-25079

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

Exploited in the wild (CISA KEV since Aug 5, 2025). NVD reports CVSS 3.1 8.8. EPSS estimates 52.7% exploit likelihood as of Aug 26, 2026.

82.683.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

State
PUBLISHED
Published
Sep 2, 2020
Updated
Oct 21, 2025
Evidence coverage
98%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    mitre

    Record text: An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

    Inspect raw assertion
    Field
    container
    Value
    An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 52.72% probability · 98.89th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.527170000000; percentile 0.988850000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Aug 5, 2025 · first observed Jul 19, 2026

Exploit likelihood52.72%

FIRST EPSS · score date Aug 26, 2026 · 98.9th percentile · first observed Aug 26, 2026

SeverityCVSS 8.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
mitreOriginal assertion
Record text

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

Inspect raw assertion
Field
container
Value
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

52.72% probability · 98.89th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.527170000000; percentile 0.988850000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
18Underlying assertions
18Canonical products
9Target assertions
9Constraint assertions

Grouped from 18 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

19 scope groups

mitre · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · HARDWAREdlinkdcs-2530lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c89191f98692b2526f827c1f4d00f66d2eef6da83a184df2f6f6b9de7a7e3270Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-2530l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40a05ff4-4847-41c2-946a-f8043481e11f
NVD CPE · OPERATING SYSTEMdlinkdcs-2530l_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (<= 1.05.05)Canonical identity product-77aae9e24bb08f2382f11297b95a1a77f30ff7803f07d493cd22622cf8c0cd50Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-2530l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 1.05.05
    Match ID
    93c1e07c-d4c7-4cb2-b0f7-01f838a3555b
NVD CPE · HARDWAREdlinkdcs-2670lEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e43d6ecec49eab17e2e5191bc861f782724cd92847df4f8a8bc1d0b17402b249Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-2670l:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f66d7ca9-66e1-4a37-88aa-2e98dc0416c0
NVD CPE · OPERATING SYSTEMdlinkdcs-2670l_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.03.00)Canonical identity product-fa5b7cda7990583b0e89134e2e7aedb619e4319e7f2efae2c3099e9d67babd79Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-2670l_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.03.00
    Match ID
    8e5964e9-1104-4430-a023-b7616b5a6217
NVD CPE · HARDWAREdlinkdcs-4603Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8d2a48dee200465647b5fb0aeec55e012f0712b4449045cf3ee2e8a3ceef7f6fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4603:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8a2c3661-5f58-4472-b5a0-9a8024788bcd
NVD CPE · OPERATING SYSTEMdlinkdcs-4603_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 1.04.02)Canonical identity product-bc7302dea07ef59c204b258f6ec165aaebfd31798e94a66c1e2fd68d694ec3ceLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4603_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 1.04.02
    Match ID
    41124e24-06be-417b-a9af-bd641a75c144
NVD CPE · HARDWAREdlinkdcs-4622Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5305a7a45f053c2e4b92188ca0bfe6f2d43a657d9a83a6b79e0cbe3dc4448080Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4622:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8ce51257-204e-4652-83c8-be139d176bd4
NVD CPE · OPERATING SYSTEMdlinkdcs-4622_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.01.10)Canonical identity product-bfbc1ce1793165eefe5340863be0515d6a575a1c2bf93cd4a89709b5ebe0fd79Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4622_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.01.10
    Match ID
    3ba3a472-3da8-4ac3-84cf-1a2e58360b5a
NVD CPE · HARDWAREdlinkdcs-4701eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-2d5744c9aa1e5866151c0faca164c3241792237237812cd6d0c908f77d9deed7Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4701e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3dd99d0-b76b-4e80-af95-4c36693ed7f3
NVD CPE · OPERATING SYSTEMdlinkdcs-4701e_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.03.01)Canonical identity product-6e06ea4cbacb39b4e7f789bfc3149227bc7d0f817b2408a804c5b16268ccc838Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4701e_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.03.01
    Match ID
    9c8b4a06-bb05-4c28-89f0-e0ef7904a903
NVD CPE · HARDWAREdlinkdcs-4703eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-f3bb8bca116ef416405db6d1b887a4cb39ea281e2ded6891174f801ee1067f8aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4703e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    76074ee9-9d8f-4dc2-8e1f-69b791cc0fe3
NVD CPE · OPERATING SYSTEMdlinkdcs-4703e_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 1.03.04)Canonical identity product-9c1113cac84062c9a0b4b675f79f226ecb8de8b2901ebd9a6fa54984e1d30b5aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4703e_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 1.03.04
    Match ID
    2a50ff8a-796d-4dc2-97a0-fa05ff8f292f
NVD CPE · HARDWAREdlinkdcs-4705eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-c7c8a4ef896cef86bd9be3e9cb96b48d1d41973f73877812c53cd8daa88c82d4Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4705e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    056553ce-a448-46ac-a84d-937f026a7659
NVD CPE · OPERATING SYSTEMdlinkdcs-4705e_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 1.03.02)Canonical identity product-473049d80434a0e8ab99daa8a6f84787e4c8f9ab642c554ad69c02064a52f564Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4705e_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 1.03.02
    Match ID
    9d1b414b-fa5d-4567-9d75-936f420d91ac
NVD CPE · HARDWAREdlinkdcs-4802eEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3f6bdf492a6c38670a2c2efbd1df12a57a0bbf93cbe889998e08e08c6180ba96Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-4802e:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    045e6932-6dc2-491d-a45c-b98b14c362bc
NVD CPE · OPERATING SYSTEMdlinkdcs-4802e_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.01.01)Canonical identity product-8e4086cec43bdb0a5d44dd26d14bc395bd25c797b0aa4886ddc82d7d940380b5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-4802e_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.01.01
    Match ID
    270e0460-481c-41a0-9954-850943ba77ce
NVD CPE · HARDWAREdlinkdcs-p703Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d30f264dc3c81c5c6c70873190e798d0a5c518ada192910ad4b386ad0240a06cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dlink:dcs-p703:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3fa4d04f-09ec-4f29-85ef-2b183b113816
NVD CPE · OPERATING SYSTEMdlinkdcs-p703_firmwareVulnerable target · 1 assertions
Any version (unconstrained)Canonical identity product-0034eaf690cadf53444f5d33228e84d2f0da31f0f2936f896085b4bbe913c33bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dlink:dcs-p703_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ade8472-8afa-431a-9e14-5fcb878025f3

Affected-product evidence

Accepted scope and product mapping

9 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-0034eaf690cadf53444f5d33228e84d2f0da31f0f2936f896085b4bbe913c33b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
790df486-8a21-4fdc-acd5-8001f278b821
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-473049d80434a0e8ab99daa8a6f84787e4c8f9ab642c554ad69c02064a52f564

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fe37865e-8583-482b-a390-d6c0b4685c8b
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-6e06ea4cbacb39b4e7f789bfc3149227bc7d0f817b2408a804c5b16268ccc838

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e29c929d-f895-4f7e-8da1-f6c4084430b8
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-77aae9e24bb08f2382f11297b95a1a77f30ff7803f07d493cd22622cf8c0cd50

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
040f3566-c84c-4226-bc98-fd589d331bd6
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-8e4086cec43bdb0a5d44dd26d14bc395bd25c797b0aa4886ddc82d7d940380b5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d7888c8f-c808-4914-9cce-520aaac02aba
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-9c1113cac84062c9a0b4b675f79f226ecb8de8b2901ebd9a6fa54984e1d30b5a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
412383ef-505a-42e5-bd17-e0367a60c26c
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-bc7302dea07ef59c204b258f6ec165aaebfd31798e94a66c1e2fd68d694ec3ce

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5d8f1dd9-5cfa-4639-a89e-eb23dd9146d7
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-bfbc1ce1793165eefe5340863be0515d6a575a1c2bf93cd4a89709b5ebe0fd79

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
afd464a4-2c1e-49e9-9b19-9471efac51e0
Mapping establishedEvidence supported

vendor-63b4eb7686e07dcd86850729591b5c1d9eee457c4dfc395dd47498ea390af81f · product-fa5b7cda7990583b0e89134e2e7aedb619e4319e7f2efae2c3099e9d67babd79

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
aa6f92a4-f097-451d-abfe-990f19385d4c
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
84c6dba3-12ab-4b2a-8672-6830c3cf7cc6

Assessments

CVSS by origin

8.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
9.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:S/C:C/I:C/A:C
8.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.