CVE-2025-4903
MEDIUMDlink Di-7003g Firmware - Password Reset Weakness
Title source: ruleDescription
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub_41F4F0 of the file /H5/webgl.asp?tggl_port=0&remote_management=0&http_passwd=game&exec_service=admin-restart. The manipulation leads to unverified password change. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
5.3
EPSS
0.0060
EPSS Percentile
69.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-620
CWE-640
Status
published
Affected Products (1)
dlink/di-7003g_firmware
Timeline
Published
May 19, 2025
Tracked Since
Feb 18, 2026