Dlink
Dlink Dir-823x Firmware: vulnerabilidades y CVE
Dlink Dir-823x Firmware tiene 39 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses17
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-29635 | Alta (7.2) | 88% | ⚠ Explotación activa | 25 mar 2025 | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2210 | Alta (7.3) | 4.1% | — | 9 feb 2026 | A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The… |
| CVE-2026-2175 | Alta (7.3) | 4.0% | — | 8 feb 2026 | A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection.… |
| CVE-2026-2157 | Alta (7.3) | 4.2% | — | 8 feb 2026 | A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument… |
| CVE-2026-2155 | Alta (7.3) | 4.1% | — | 8 feb 2026 | A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument… |
| CVE-2026-2143 | Alta (7.3) | 4.6% | — | 8 feb 2026 | A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument… |
| CVE-2026-2142 | Alta (7.3) | 6.0% | — | 8 feb 2026 | A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a manipulation can lead to os command injection. The attack can be… |
| CVE-2026-2129 | Alta (7.3) | 4.6% | — | 8 feb 2026 | A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performing a manipulation of the argument ac_ipaddr/ac_ipstatus/ap_randtime… |
| CVE-2026-2120 | Alta (7.3) | 4.2% | — | 8 feb 2026 | A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument… |
| CVE-2026-2084 | Alta (7.3) | 4.1% | — | 7 feb 2026 | A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is… |
| CVE-2026-2082 | Baja (2) | 5.2% | — | 7 feb 2026 | A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack… |
| CVE-2026-2081 | Baja (2) | 5.6% | — | 7 feb 2026 | A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The… |
| CVE-2026-2063 | Baja (2) | 4.7% | — | 6 feb 2026 | A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of the argument… |
| CVE-2026-2061 | Baja (2) | 4.6% | — | 6 feb 2026 | A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It is possible to… |
| CVE-2026-1685 | Baja (2.9) | 1.2% | — | 30 ene 2026 | A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts.… |
| CVE-2026-1544 | Baja (2.1) | 3.8% | — | 28 ene 2026 | A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of the argument lan_gateway results in os command injection. The… |
| CVE-2026-1125 | Media (5.5) | 16% | — | 18 ene 2026 | A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to… |
| CVE-2025-14208 | Baja (2.1) | 3.4% | — | 8 dic 2025 | A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command… |
| CVE-2025-11100 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack… |
| CVE-2025-11099 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is… |
| CVE-2025-11097 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to… |
| CVE-2025-11096 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr can lead to command injection. The… |
| CVE-2025-11098 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injection. The attack… |
| CVE-2025-11092 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. This manipulation of the argument port causes command injection. The… |
| CVE-2025-11095 | Baja (2.1) | 4.1% | — | 28 sept 2025 | A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing manipulation of the argument delvalue results in command injection.… |
| CVE-2025-55848 | Alta (8.8) | 0.41% | — | 26 sept 2025 | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection… |
| CVE-2025-10814 | Baja (2.1) | 6.1% | — | 22 sept 2025 | A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command… |
| CVE-2025-10634 | Baja (2.1) | 7.4% | — | 18 sept 2025 | A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of… |
| CVE-2025-10401 | Baja (2.1) | 8.2% | — | 14 sept 2025 | A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection.… |
| CVE-2025-10123 | Media (5.5) | 4.7% | — | 9 sept 2025 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead… |
| CVE-2025-29039 | Alta (7.2) | 1.3% | — | 17 abr 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8 |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.