PT-2025-39757 · D Link · Dir-823

Neptune111

·

Published

2025-09-09

·

Updated

2025-09-30

·

CVE-2025-11095

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A command injection issue exists in D-Link DIR-823X version 250416. The issue is located in the file /goform/delete offline device. Manipulation of the delvalue argument can lead to command injection. Remote exploitation is possible. The exploit is publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12540
CVE-2025-11095

Affected Products

Dir-823