CVE-2025-4901: D-Link DI-7003GV2 HTTP Endpoint state_view.data sub_41E304 information disclosure
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub41E304 of the file /H5/stateview.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4901?
CVE-2025-4901 is classified as problematic due to its potential for information disclosure.
How do I fix CVE-2025-4901?
To fix CVE-2025-4901, apply the latest firmware updates provided by D-Link for the DI-7003GV2 model.
What type of attack does CVE-2025-4901 involve?
CVE-2025-4901 involves an information disclosure vulnerability that may allow an attacker to access sensitive data.
Which D-Link product is affected by CVE-2025-4901?
CVE-2025-4901 affects the D-Link DI-7003GV2 model.
Is there a workaround for CVE-2025-4901?
Currently, the most effective approach to mitigate CVE-2025-4901 is to ensure the device firmware is updated to the latest version.