PT-2025-12801 · D Link · Dir-823
Published
2025-03-25
·
Updated
2026-04-23
·
CVE-2025-29635
CVSS v2.0
9.0
High
| AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X versions 240126 through 240802
Description
A command injection issue allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to "/goform/set prohibiting" via the corresponding function, triggering remote command execution.
Recommendations
For versions 240126 through 240802, consider disabling the function that triggers the command injection via the "/goform/set prohibiting" endpoint until a patch is available.
Restrict access to the "/goform/set prohibiting" endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dir-823