PT-2026-6775 · D Link · D-Link Dir-823G
Jiefengliang
·
Published
2026-01-22
·
Updated
2026-02-06
·
CVE-2026-2063
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X version 250416
Description
A security flaw exists in the D-Link DIR-823X version 250416. The issue is located in the Web Management Interface, specifically within the file
/goform/set ac server. Manipulation of the ac server argument can lead to os command injection. This attack can be initiated remotely. The exploit for this issue has been publicly released.Recommendations
Apply updates to address the vulnerability in the Web Management Interface.
Restrict access to the
/goform/set ac server file.
As a temporary workaround, consider disabling the Web Management Interface until a patch is available.Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-823G