PT-2025-36565 · D Link · Dir-823
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X versions prior to 250416
Description
A command injection issue exists in the
sub 415028 function within the /goform/set static leases endpoint. The flaw is caused by insufficient input validation of the Hostname variable. A remote attacker can exploit this by sending a specially crafted request to execute arbitrary commands on the device, potentially gaining full control.Recommendations
Update the firmware to a version newer than 250416.
Disable WAN administration.
Restrict management access to the local area network (LAN).
Exploit
Fix
RCE
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-823