# CVE-2025-14528: DIR-803 - Information Disclosure

> Live exploitation tracking for CVE-2025-14528 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2025-14528

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 6.9
- **Public exploit available:** Yes
- **Affected products:** D-Link DIR-803
- **Weaknesses:** CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor); CWE-284 (Improper Access Control)
- **Tags:** iot

## Description

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

## CrowdSec analysis

[CVE-2025-14528](https://euvd.enisa.europa.eu/vulnerability/CVE-2025-14528) is an information disclosure vulnerability in D-Link DIR-803 routers up to firmware version 1.04, specifically within the /getcfg.php configuration handler. By manipulating the AUTHORIZED_GROUP argument, remote attackers can exploit this flaw to access sensitive configuration data without authentication. The exploit is publicly available, increasing the risk of unauthorized data exposure, especially since these devices are no longer supported by the vendor.

CrowdSec has been tracking this vulnerability and its exploits since 18th of February 2026.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2025-14528 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning.
CrowdSec network telemetry also shows that exploitation of CVE-2025-14528 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers exploit the `/getcfg.php` endpoint by injecting newline characters and manipulating the `AUTHORIZED_GROUP` parameter to bypass authentication and retrieve sensitive XML configuration data, including administrator credentials.

## Timeline

- 2025-12-11: CVE Published. CVE-2025-14528 is published to NVD.
- 2026-02-18: Rule Released. CrowdSec releases a rule to detect CVE-2025-14528 exploitation attempts against the CrowdSec Network.
- 2026-02-20: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2025-14528 for the first time.

## References

- https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.md#poc
- https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.md
- https://www.dlink.com/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-14528.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2025-14528) follows observed exploitation activity for CVE-2025-14528. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
