PT-2026-6775 · D Link · D-Link Dir-823G

·

CVE-2026-2063

·

Published

2026-01-22

·

Updated

2026-02-06

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A security flaw exists in the D-Link DIR-823X version 250416. The issue is located in the Web Management Interface, specifically within the file /goform/set ac server. Manipulation of the ac server argument can lead to os command injection. This attack can be initiated remotely. The exploit for this issue has been publicly released.
Recommendations Apply updates to address the vulnerability in the Web Management Interface. Restrict access to the /goform/set ac server file. As a temporary workaround, consider disabling the Web Management Interface until a patch is available.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02160
CVE-2026-2063

Affected Products

D-Link Dir-823G