PT-2025-5980 · D Link · Dir-823
Hand_King
·
Published
2025-02-07
·
Updated
2025-06-20
·
CVE-2025-1103
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X versions 240126 through 240802
Description
A problematic issue was found in the HTTP POST Request Handler component, specifically affecting the
set wifi blacklists function of the /goform/set wifi blacklists file. The manipulation of the macList argument leads to a null pointer dereference. This issue can be exploited remotely.Recommendations
For versions 240126 through 240802, as a temporary workaround, consider disabling the
set wifi blacklists function until a patch is available. Restrict access to the /goform/set wifi blacklists endpoint to minimize the risk of exploitation. Avoid using the macList argument in the affected HTTP POST Request Handler until the issue is resolved.Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-823