PT-2025-46879 · D Link · D-Link Dir-823G

Published

2025-11-13

·

Updated

2025-11-13

·

CVE-2025-60671

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-823G router firmware version DIR823G V1.0.2B05 20181207.bin
Description A command injection issue exists in the D-Link DIR-823G router firmware. The timelycheck and sysconf binaries process the /var/system/linux vlan reinit file. The issue arises because content read from this file undergoes only partial validation of a prefix and is then formatted using the vsnprintf() function before being executed with system(). This allows an attacker with write access to /var/system/linux vlan reinit to execute arbitrary commands on the device. The vulnerable components are timelycheck and sysconf.
Recommendations Update to a newer version of the D-Link DIR-823G router firmware that addresses this issue. As a temporary workaround, restrict write access to the /var/system/linux vlan reinit file to prevent unauthorized command execution.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14853
CVE-2025-60671

Affected Products

D-Link Dir-823G