A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
|
CPEs | cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:* |
|
Vendors & Products |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
Tue, 25 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-25T14:50:51.121Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29635

Updated: 2025-03-25T14:49:53.234Z

Status : Analyzed
Published: 2025-03-25T14:15:29.043
Modified: 2025-04-03T17:35:51.163
Link: CVE-2025-29635

No data.