A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
2025-03-25T14:15:29.043
2025-04-03T17:35:51.163
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-823x_firmware | 240126 | Yes |
Operating System | dlink | dir-823x_firmware | 240802 | Yes |
Hardware | dlink | dir-823x | - | No |