cbcvebase.
CVE-2025-2359
published 2025-03-17

CVE-2025-2359: A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the…

PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.01%
96.1th percentile
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Affected

2 ranges
VendorProductVersion rangeFixed in
d-linkdir-823g
dlinkdir-823g_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/HNAP1/
otherSOAPAction: "http://purenetworks.com/HNAP1/Set(DDNSSettings|UpnpSettings)"
  • Request body must contain an XML element beginning with <SetDDNSSettings or <SetUpnpSettings (|3c|Set followed by DDNSSettings or UpnpSettings and a space) to confirm exploitation attempt.
  • Traffic is plaintext HTTP (not TLS); deploy detection at perimeter and internal network boundaries targeting dest_ip (the D-Link device).
  • MITRE mapping: TA0001 Initial Access / T1190 Exploit Public-Facing Application — treat alerts as potential initial access attempts against D-Link DIR-823G networking equipment.
  • ·The vulnerability only affects D-Link DIR-823G firmware version 1.0.2B05_20181207, which is end-of-life and will not receive patches from the vendor.
  • ·The Snort/Suricata rule (sid:2061622) covers both CVE-2025-2359 (SetDDNSSettings) and CVE-2025-2360 (SetUpnpSettings) in a single signature; tune or split if per-CVE granularity is required.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.