CVE-2025-14528General(dlink / dir-803)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-803
  • dir-803_firmware

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
dir-803dir-803_firmware

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-23: 1Mentions · 2026-06-07: 1Technical Details · 2026-02-23: 1Technical Details · 2026-06-07: 102-2306-07
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-231
General1
2026-06-071
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-14528 - high 🚨 D-Link DIR-803 - Authentication Bypass > An authentication bypass vulnerability exists in D-Link DIR-803 routers (firmware A1 ... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-14528 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2025-14528 is disclosed as an authentication bypass on D-Link DIR-803 routers (firmware A1); no PoC, exploit, patch, or active exploitation details are provided.

    0102186
    952 followersView on X
  • CrowdSec@Crowd_Security
    General

    🚨 This week’s CrowdSec Threat Alert: CVE-2025-14528, a remotely exploitable vulnerability in end-of-life D-Link DIR-803 routers, is exposing admin credentials and opening the door to botnet recruitment. Discover how the exploit works, what early scanning activity reveals, and why legacy routers remain prime low-level cybercriminal targets in our latest article 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-14528 #CVE #CVE202514528 #threatalert #cybersecurity

    Post summary

    The article discusses a remotely exploitable CVE in legacy D‑Link routers that could expose admin credentials and aid botnet recruitment, but it provides no PoC, exploit code, or patch information.

    00020276
    19.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-803a1--
OSdlinkdir-803_firmware---

Explore more