PT-2026-3398 · D Link · D-Link Dir-823G

Yun Zhang

·

Published

2026-01-09

·

Updated

2026-01-30

·

CVE-2026-1125

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A flaw exists in D-Link DIR-823X 250416 that allows for command injection. This occurs due to a manipulation of the wd enable argument within the sub 412E7C function of the /goform/set wifidog settings file. The attack can be carried out remotely. The exploit is publicly available.
Recommendations Apply any available updates to address the issue in the affected version. As a temporary workaround, consider restricting access to the /goform/set wifidog settings file. Avoid manipulating the wd enable argument in the /goform/set wifidog settings file.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00682
CVE-2026-1125

Affected Products

D-Link Dir-823G