D-Link DIR-803 - Authentication Bypass
CVE-2025-14528
Verified
Description
An authentication bypass vulnerability exists in D-Link DIR-803 routers (firmware A1 1.04 and earlier). By manipulating the AUTHORIZED_GROUP parameter in /getcfg.php via newline injection, an attacker can retrieve XML configuration containing administrator credentials without authentication.
Severity
High
CVSS Score
5.3
Exploit Probability
4%
Published Date
February 10, 2026
Template Author
dhiyaneshdk
CVE-2025-14528.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-14528
CWE ID:
cwe-200
Remediation Steps
Upgrade to the latest supported version or replace the device as it is no longer maintained.