PT-2026-6939 · D Link · Dir-823

942384053

·

Published

2026-02-08

·

Updated

2026-02-13

·

CVE-2026-2120

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X version 250416
Description A flaw exists in the Configuration Parameter Handler component of D-Link DIR-823X version 250416. The issue stems from manipulating the terminal addr, server ip, and server port arguments within the /goform/set server settings file, leading to operating system command injection. This allows for remote attacks. The exploit is publicly available.
Recommendations Apply a firmware update that addresses the vulnerability in the Configuration Parameter Handler component. As a temporary workaround, restrict access to the /goform/set server settings file. Avoid using the terminal addr, server ip, and server port parameters until the issue is resolved.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2120

Affected Products

Dir-823