PT-2026-6939 · D Link · Dir-823
942384053
·
Published
2026-02-08
·
Updated
2026-02-13
·
CVE-2026-2120
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X version 250416
Description
A flaw exists in the Configuration Parameter Handler component of D-Link DIR-823X version 250416. The issue stems from manipulating the
terminal addr, server ip, and server port arguments within the /goform/set server settings file, leading to operating system command injection. This allows for remote attacks. The exploit is publicly available.Recommendations
Apply a firmware update that addresses the vulnerability in the Configuration Parameter Handler component. As a temporary workaround, restrict access to the
/goform/set server settings file. Avoid using the terminal addr, server ip, and server port parameters until the issue is resolved.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-823