PT-2026-6943 · D Link · D-Link Dir-823G
Jiefengliang
·
Published
2026-01-24
·
Updated
2026-02-13
·
CVE-2026-2129
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823X version 250416
Description
A flaw exists in D-Link DIR-823X version 250416 related to the processing of input for the file
/goform/set ac status. Manipulation of the ac ipaddr, ac ipstatus, and ap randtime arguments can lead to os command injection. This issue can be exploited remotely. The exploit has been publicly released.Recommendations
Apply any available updates to address the vulnerability in the affected file
/goform/set ac status.
As a temporary workaround, restrict access to the /goform/set ac status file to minimize the risk of exploitation.
Avoid manipulating the ac ipaddr, ac ipstatus, and ap randtime arguments.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-823G