CVE-2025-4901

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.309457 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.309457 Third Party Advisory VDB Entry
https://vuldb.com/?submit.578049 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:di-7003g_firmware:24.04.18d1_r\(68125\):*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7003g:v2.d1:*:*:*:*:*:*:*

History

21 May 2025, 13:40

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en D-Link DI-7003GV2 24.04.18D1 R(68125). Esta vulnerabilidad afecta la función sub_41E304 del archivo /H5/state_view.data del componente HTTP Endpoint. La manipulación provoca la divulgación de información. El ataque solo puede realizarse dentro de la red local. Se ha hecho público el exploit y puede que sea utilizado.
References () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md - () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.309457 - () https://vuldb.com/?ctiid.309457 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.309457 - () https://vuldb.com/?id.309457 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.578049 - () https://vuldb.com/?submit.578049 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
CWE NVD-CWE-noinfo
First Time Dlink
Dlink di-7003g
Dlink di-7003g Firmware
CPE cpe:2.3:o:dlink:di-7003g_firmware:24.04.18d1_r\(68125\):*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7003g:v2.d1:*:*:*:*:*:*:*

19 May 2025, 14:15

Type Values Removed Values Added
References () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md - () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md -

19 May 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 00:15

Updated : 2025-05-21 13:40


NVD link : CVE-2025-4901

Mitre link : CVE-2025-4901

CVE.ORG link : CVE-2025-4901


JSON object : View

Products Affected

dlink

  • di-7003g_firmware
  • di-7003g
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo