← back
CVE-2025-29635

CVE-2025-29635

CVSS 7.2 HIGHEPSS 35.1%● KEVCWE-77
In short

An authorized user can execute arbitrary commands on D-Link DIR-823X routers by sending a specially crafted request, potentially allowing them to take complete control of the device.

Technical detail

Command injection vulnerability in POST endpoint /goform/set_prohibiting allows authenticated attackers to inject OS commands through unsanitized input parameters. The vulnerability affects D-Link DIR-823X versions 240126 and 240802, resulting in unauthenticated remote code execution with device privileges.

Summary generated and translated by AI from the official description.
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →