CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2025-14528Public Exploit

DIR-803 - Information Disclosure (CVE-2025-14528)

PublishedDec 11, 2025
First SeenFeb 20, 2026
Last Seen
Reported
CVSS6.9
iot

Description

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

psychologyCrowdSec Analysis

CVE-2025-14528 is an information disclosure vulnerability in D-Link DIR-803 routers up to firmware version 1.04, specifically within the /getcfg.php configuration handler. By manipulating the AUTHORIZED_GROUP argument, remote attackers can exploit this flaw to access sensitive configuration data without authentication. The exploit is publicly available, increasing the risk of unauthorized data exposure, especially since these devices are no longer supported by the vendor.

CrowdSec has been tracking this vulnerability and its exploits since 18th of February 2026.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2025-14528 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning. CrowdSec network telemetry also shows that exploitation of CVE-2025-14528 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers exploit the /getcfg.php endpoint by injecting newline characters and manipulating the AUTHORIZED_GROUP parameter to bypass authentication and retrieve sensitive XML configuration data, including administrator credentials.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2025-12-11
Rule Released2026-02-18
CrowdSec First Seen2026-02-20

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.