CVE-2025-9003: D-Link DIR-818LW DHCP Reserved Address bsc_lan.php cross site scripting
A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsclan.php of the component DHCP Reserved Address Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9003?
CVE-2025-9003 is classified as a high severity vulnerability due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2025-9003?
To mitigate CVE-2025-9003, update the D-Link DIR-818LW firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2025-9003?
CVE-2025-9003 is a cross-site scripting (XSS) vulnerability affecting the DHCP Reserved Address Handler in D-Link DIR-818LW devices.
Who is affected by CVE-2025-9003?
Users of the D-Link DIR-818LW router with the firmware version 1.04 are affected by CVE-2025-9003.
Can CVE-2025-9003 be exploited remotely?
Yes, CVE-2025-9003 can be exploited remotely, allowing attackers to execute malicious scripts without physical access to the device.