/Vulnerability Library

D-Link DIR-803 - Authentication Bypass

CVE-2025-14528
Verified

Description

An authentication bypass vulnerability exists in D-Link DIR-803 routers (firmware A1 1.04 and earlier). By manipulating the AUTHORIZED_GROUP parameter in /getcfg.php via newline injection, an attacker can retrieve XML configuration containing administrator credentials without authentication.

Severity

High

CVSS Score

5.3

Exploit Probability

4%

Published Date

February 10, 2026

Template Author

dhiyaneshdk

CVE-2025-14528.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-14528
CWE ID:
cwe-200

References

https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.mdhttps://vuldb.com/?id.335869https://nvd.nist.gov/vuln/detail/CVE-2025-14528

Remediation Steps

Upgrade to the latest supported version or replace the device as it is no longer maintained.