ZeroHour

CVE-2025-4901

PoC niche

Information disclosure in D-Link DI-7003GV2 router HTTP endpoint

CVSS 4.0
5.3 medium
EPSS
77%p100
Published
()
Modified
AI analysis

An information-disclosure flaw (CWE-200/CWE-284) exists in the D-Link DI-7003GV2 router running firmware 24.04.18D1 R(68125): the function sub_41E304 handling /H5/state_view.data in the device's HTTP endpoint mishandles requests and leaks information. An unauthenticated attacker who is already on the local network can trigger it by sending crafted requests to the router's web management interface (CVSS 4.0 reflects adjacent-network attack, no privileges, no user interaction). The attacker gains access to sensitive information exposed by that endpoint (low confidentiality impact); device integrity and availability are unaffected. Operators of DI-7003GV2 units with the affected firmware are affected, though only where the web interface is reachable from the local network. A public proof-of-concept is available; the flaw is not yet in CISA KEV, but a 77.3% EPSS probability (100th percentile) indicates a high likelihood of exploitation within 30 days.

What to do: Check the device's firmware version against 24.04.18D1 R(68125) and apply D-Link's fixed firmware once released (no fixed version is specified in current disclosures, so do not assume an upgrade target yet). Until patching, keep the web management interface off the WAN and restrict it to a trusted management VLAN or specific admin hosts, and segment guest/untrusted devices away from the router's LAN, since the flaw is only reachable locally. Given the public PoC and high EPSS, watch device logs for unexpected requests to /H5/state_view.data.

Affected
D-Link DI-7003GV2 (DI-7003G firmware)24.04.18D1 R(68125) (the version cited as affected; broader affected ranges were not specified in the disclosure)
Estimated exposure
nichelikely thousands of deployed routers at most (single niche business-model line; no public install-base figures) — No public install-base counts or internet-scan data exist for this specific D-Link business router model, so the estimate is bounded by it being one niche product line, with the LAN-only attack surface further limiting practical exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.

Vendors
dlink
Products
di-7003g firmware
Weakness
CWE-200, CWE-284
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.