An authentication bypass vulnerability exists in D-Link DIR-803 routers (firmware A1 1.04 and earlier). By manipulating the AUTHORIZED_GROUP parameter in /getcfg.php via newline injection, an attacker can retrieve XML configuration containing administrator credentials without authentication.
id: CVE-2025-14528
info:
name: D-Link DIR-803 - Authentication Bypass
author: DhiyaneshDk
sev
...