← voltar
CVE-2025-14528mediumexploração observadaCWE-200CWE-284

D-Link DIR-803 Configuration getcfg.php information disclosure

50Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 6.9epss 4.0%
da publicação à arma
Publicada no NVD11 de dez.
VulnCheck+71d
probabilidade de exploração
4.0%top 10% das CVEs
exploração observada
simVulnCheck
A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Produtos afetados
D-Link · DIR-803