PT-2026-6939 · D Link · Dir-823

942384053

·

Publicado

2026-02-08

·

Atualizado

2026-02-13

·

CVE-2026-2120

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A flaw exists in the Configuration Parameter Handler component of D-Link DIR-823X version 250416. The issue stems from manipulating the terminal addr, server ip, and server port arguments within the /goform/set server settings file, leading to operating system command injection. This allows for remote attacks. The exploit is publicly available.
Recommendations Apply a firmware update that addresses the vulnerability in the Configuration Parameter Handler component. As a temporary workaround, restrict access to the /goform/set server settings file. Avoid using the terminal addr, server ip, and server port parameters until the issue is resolved.

Exploit

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2120

Produtos afetados

Dir-823