A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
History

Wed, 21 May 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink di-7003g
Dlink di-7003g Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:dlink:di-7003g:v2.d1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:di-7003g_firmware:24.04.18d1_r\(68125\):*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink di-7003g
Dlink di-7003g Firmware

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 18 May 2025 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
Title D-Link DI-7003GV2 HTTP Endpoint state_view.data sub_41E304 information disclosure
Weaknesses CWE-200
CWE-284
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:A/AC:L/Au:N/C:P/I:N/A:N'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-18T23:31:04.835Z

Updated: 2025-05-19T14:01:07.425Z

Reserved: 2025-05-17T13:06:08.268Z

Link: CVE-2025-4901

cve-icon Vulnrichment

Updated: 2025-05-19T14:00:55.991Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-19T00:15:17.400

Modified: 2025-05-21T13:40:20.293

Link: CVE-2025-4901

cve-icon Redhat

No data.