CVE-2025-4903: D-Link DI-7003GV2 webgl.asp sub_41F4F0 unverified password change
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub41F4F0 of the file /H5/webgl.asp?tgglport=0&remotemanagement=0&httppasswd=game&execservice=admin-restart. The manipulation leads to unverified password change. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4903?
CVE-2025-4903 is classified as a critical vulnerability.
How does CVE-2025-4903 affect D-Link DI-7003GV2?
CVE-2025-4903 affects the remote management function of D-Link DI-7003GV2, potentially allowing unverified password manipulations.
What is the potential impact of exploiting CVE-2025-4903?
Exploiting CVE-2025-4903 could lead to unauthorized administrative access and control over the device.
How can I mitigate the risks associated with CVE-2025-4903?
To mitigate risks associated with CVE-2025-4903, ensure your D-Link DI-7003GV2 device firmware is updated to the latest version.
Is there a patch available for CVE-2025-4903?
As of now, there is no specific patch publicly available for CVE-2025-4903, but checking for firmware updates regularly is advisable.