CVE-2025-14528Medium· 5.3▾ TwilightPoC availableA vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosur…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.0%
Nuclei ×1 (last check)
A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
dir-803_firmware <= 1.04Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14659High· 8.8A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-15194Critical· 9.8A vulnerability was found in D-Link DIR-600 up to 2.15WWb02
CVE-2025-15193High· 8.8A vulnerability was detected in D-Link DWR-M920 up to 1.1.50
CVE-2025-15192Medium· 6.3A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50
CVE-2025-15190High· 8.8A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50