D-Link DI-7003GV2 Information Disclosure Vulnerability

Vulnerability

An information disclosure vulnerability has been identified in the D-Link DI-7003GV2 router, specifically in the firmware version 24.04.18D1 R(68125). The vulnerability resides in the '/H5/webgl.data' endpoint, within the function 'sub_41F0FC'. This issue allows remote attackers to access sensitive device configuration information without authentication. The exposed data includes HTTP ports, usernames, SSH and Telnet settings, remote management configurations, and more.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive system information, potentially including device configuration details and user credentials.

Remediation

It is recommended to implement proper firewalling to mitigate this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.