CVE-2025-14528: DIR-803 <=1.04 Info Disclosure via /getcfg.php AUTHORIZED_GROUP
CVE-2025-14528 Published on December 11, 2025

D-Link DIR-803 Configuration getcfg.php information disclosure
A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2025-14528 has been classified to as an Information Disclosure vulnerability or weakness.

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2025-14528 has been classified to as an Authorization vulnerability or weakness.


Affected Versions

D-Link DIR-803 Version 1.04 is affected by CVE-2025-14528

Exploit Probability

EPSS
6.95%
Percentile
91.31%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.