A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument interface/destip/netmask/gateway/metric leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
2026-02-08T15:15:52.310
2026-02-11T18:44:32.140
Analyzed
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:M/C:C/I:C/A:C
6.4
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | dlink | dir-823x_firmware | 250416 | Yes |
| Hardware | dlink | dir-823x | - | No |