CVE-2025-4901

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.309457 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.309457 Third Party Advisory VDB Entry
https://vuldb.com/?submit.578049 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:di-7003g_firmware:24.04.18d1_r\(68125\):*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7003g:v2.d1:*:*:*:*:*:*:*

History

21 May 2025, 13:40

Type Values Removed Values Added
First Time Dlink di-7003g Firmware
Dlink
Dlink di-7003g
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:dlink:di-7003g_firmware:24.04.18d1_r\(68125\):*:*:*:*:*:*:*
cpe:2.3:h:dlink:di-7003g:v2.d1:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://vuldb.com/?submit.578049 - () https://vuldb.com/?submit.578049 - Third Party Advisory, VDB Entry
References () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md - () https://github.com/at0de/my_vulns/blob/main/Dlink/Di-7003GV2/state_view.md - Exploit, Third Party Advisory
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
References () https://vuldb.com/?ctiid.309457 - () https://vuldb.com/?ctiid.309457 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.309457 - () https://vuldb.com/?id.309457 - Third Party Advisory, VDB Entry

19 May 2025, 14:15

Type Values Removed Values Added
CWE CWE-284
CWE-200
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown

19 May 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 00:15

Updated : 2025-05-21 13:40


NVD link : CVE-2025-4901

Mitre link : CVE-2025-4901


JSON object : View

Products Affected

dlink

  • di-7003g_firmware
  • di-7003g