« Volver al listado

Dlink

Dlink Dir-823x Firmware: vulnerabilidades y CVE

Dlink Dir-823x Firmware tiene 39 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE39
Últimos 12 meses17
Críticas5
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-29635Alta (7.2)88%⚠ Explotación activa25 mar 2025
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-2210Alta (7.3)4.1%—9 feb 2026
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The…
CVE-2026-2175Alta (7.3)4.0%—8 feb 2026
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection.…
CVE-2026-2157Alta (7.3)4.2%—8 feb 2026
A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument…
CVE-2026-2155Alta (7.3)4.1%—8 feb 2026
A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument…
CVE-2026-2143Alta (7.3)4.6%—8 feb 2026
A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument…
CVE-2026-2142Alta (7.3)6.0%—8 feb 2026
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a manipulation can lead to os command injection. The attack can be…
CVE-2026-2129Alta (7.3)4.6%—8 feb 2026
A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performing a manipulation of the argument ac_ipaddr/ac_ipstatus/ap_randtime…
CVE-2026-2120Alta (7.3)4.2%—8 feb 2026
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument…
CVE-2026-2084Alta (7.3)4.1%—7 feb 2026
A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is…
CVE-2026-2082Baja (2)5.2%—7 feb 2026
A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack…
CVE-2026-2081Baja (2)5.6%—7 feb 2026
A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The…
CVE-2026-2063Baja (2)4.7%—6 feb 2026
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of the argument…
CVE-2026-2061Baja (2)4.6%—6 feb 2026
A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It is possible to…
CVE-2026-1685Baja (2.9)1.2%—30 ene 2026
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts.…
CVE-2026-1544Baja (2.1)3.8%—28 ene 2026
A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of the argument lan_gateway results in os command injection. The…
CVE-2026-1125Media (5.5)16%—18 ene 2026
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to…
CVE-2025-14208Baja (2.1)3.4%—8 dic 2025
A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command…
CVE-2025-11100Baja (2.1)4.1%—28 sept 2025
A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is possible to launch the attack…
CVE-2025-11099Baja (2.1)4.1%—28 sept 2025
A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is…
CVE-2025-11097Baja (2.1)4.1%—28 sept 2025
A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to…
CVE-2025-11096Baja (2.1)4.1%—28 sept 2025
A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr can lead to command injection. The…
CVE-2025-11098Baja (2.1)4.1%—28 sept 2025
A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injection. The attack…
CVE-2025-11092Baja (2.1)4.1%—28 sept 2025
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. This manipulation of the argument port causes command injection. The…
CVE-2025-11095Baja (2.1)4.1%—28 sept 2025
A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing manipulation of the argument delvalue results in command injection.…
CVE-2025-55848Alta (8.8)0.41%—26 sept 2025
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection…
CVE-2025-10814Baja (2.1)6.1%—22 sept 2025
A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command…
CVE-2025-10634Baja (2.1)7.4%—18 sept 2025
A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of…
CVE-2025-10401Baja (2.1)8.2%—14 sept 2025
A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection.…
CVE-2025-10123Media (5.5)4.7%—9 sept 2025
A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead…
CVE-2025-29039Alta (7.2)1.3%—17 abr 2025
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter16
  2. T1210 Exploitation of Remote Services13
  3. T1190 Exploit Public-Facing Application5
  4. T1499 Endpoint Denial of Service1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Dlink