Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-29635


A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.


Published

2025-03-25T14:15:29.043

Last Modified

2025-04-03T17:35:51.163

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-823x_firmware 240126 Yes
Operating System dlink dir-823x_firmware 240802 Yes
Hardware dlink dir-823x - No

References