PT-2025-39758 · D Link · Dir-823

Neptune111

·

Published

2025-09-09

·

Updated

2025-09-30

·

CVE-2025-11096

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A flaw exists in the processing of the /goform/diag traceroute file within D-Link DIR-823X version 250416. Manipulation of the target addr argument can lead to command injection, allowing for remote execution. The exploit for this issue has been published.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-12543
CVE-2025-11096

Affected Products

Dir-823