CVE-2025-29635
published 2025-03-25CVE-2025-29635: A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending…
PriorityP189high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-05-08
Exploited in the wild
EPSS
87.24%
99.7th percentile
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-823x_firmware | — | — |
| dlink | dir-823x_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
sigma↗
POST /goform/set_prohibiting with macaddr parameter containing shell metacharacters (||, ;, &)
- →Detect POST requests to /goform/set_prohibiting endpoint on D-Link DIR-823X devices; inspect the 'macaddr' parameter for shell injection metacharacters (||, ;, &, backtick). ↗
- →Hunt for outbound wget/curl requests from D-Link DIR-823X devices fetching 'dlink.sh' from external IPs, indicative of the tuxnokill Mirai variant dropper stage. ↗
- →Monitor for the 'tuxnokill' Mirai botnet variant process name or DDoS traffic patterns (TCP SYN/ACK/STOMP, UDP floods, HTTP null) originating from DIR-823X devices. ↗
- →Use Shodan query 'title:"D-Link"' or FOFA query 'title="DIR-823X"' to identify internet-exposed vulnerable devices for proactive blocking or monitoring. ↗
- →The same threat actor also exploits CVE-2023-1389 (TP-Link) and an RCE in ZTE ZXV10 H108L with the same attack pattern; correlate multi-CVE exploitation campaigns targeting these device families. ↗
- →Check Point IPS signature available: 'D-Link DIR-823X Command Injection (CVE-2025-29635)' — deploy for network-level detection. ↗
- ·Exploitation requires the attacker to be authenticated/authorized on the device; unauthenticated exploitation is not indicated by current reporting. ↗
- ·Affected firmware versions are 240126 and 240802 only; devices are end-of-life (EoL) as of November 2024 and no patch is expected from D-Link. ↗
- ·A PoC exploit was briefly published on GitHub by the original researchers but was subsequently retracted. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m9wc-3h85-pp63: A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices b
ghsa_unreviewed·2025-03-25
CVE-2025-29635 [HIGH] CWE-77 GHSA-m9wc-3h85-pp63: A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices b
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
VulnCheck
D-Link dir-823x_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
vulncheck·2025·CVSS 8.8
CVE-2025-29635 [HIGH] D-Link dir-823x_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
D-Link dir-823x_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Affected: D-Link dir-823x_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices
CISA
D-Link DIR-823X Command Injection Vulnerability
cisa·2026-04-24·CVSS 8.8
CVE-2025-29635 [HIGH] CWE-77 D-Link DIR-823X Command Injection Vulnerability
Vulnerability: D-Link DIR-823X Command Injection Vulnerability
Affected: D-Link DIR-823X
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 ; https://nvd.nist.gov/vuln/detail/CVE-2025-29635
Remediation Due Date: 2026-05-08
No detection rules found.
Nuclei
D-Link DIR-823X set_prohibiting - Command Injection
nuclei·CVSS 7.2
CVE-2025-29635 [HIGH] D-Link DIR-823X set_prohibiting - Command Injection
D-Link DIR-823X set_prohibiting - Command Injection
D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POST request to /goform/set_prohibiting, letting an authorized attacker execute arbitrary commands remotely, exploit requires attacker to be authorized.
Template:
id: CVE-2025-29635
info:
name: D-Link DIR-823X set_prohibiting - Command Injection
author: pussycat0x
severity: high
description: |
D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POST request to /goform/set_prohibiting, letting an authorized attacker execute arbitrary commands remotely, exploit requires attacker to be authorized.
impact: |
Attackers can execute arbitrary commands on the device remotely, potentially leading to full device compromise.
remediatio
Hackernews
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
blogs_hackernews·2026-06-30·CVSS 8.8
CVE-2017-17215 [HIGH] RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.
Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.
The end goal is a distributed denial-of-service (DDoS) attack: flooding a target with junk traffic from the infected machines until it buckles.
RustDuck is one more entrant in a crowded field, b
Checkpoint
27th April – Threat Intelligence Report
blogs_checkpoint·2026-04-27
CVE-2025-55182 27th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee information, internal logs, and a subset of environment variables, while stating that the most sensiti
Hackernews
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
blogs_hackernews·2026-04-25·CVSS 9.9
CVE-2024-57726 [CRITICAL] CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The list of vulnerabilities is below -
CVE-2024-57726 (CVSS score: 9.9) - A missing authorization vulnerability in SimpleHelp that could allow low-privileged technicians to create API keys with excessive permissions, which can then be used to escalate privileges to the server admi
Bleepingcomputer
New Mirai campaign exploits RCE flaw in EoL D-Link routers
blogs_bleepingcomputer·2026-04-22·CVSS 8.8
CVE-2025-29635 [HIGH] New Mirai campaign exploits RCE flaw in EoL D-Link routers
## New Mirai campaign exploits RCE flaw in EoL D-Link routers
## Bill Toulas
"The Akamai SIRT discovered active exploitation attempts of the D-Link command injection vulnerability CVE-2025-29635 in our global network of honeypots in early March 2026," reads Akamai's report .
"This vulnerability exists in D-Link DIR-823X series routers in firmware versions 240126 and 24082, and allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to the /goform/set_prohibiting endpoint via the corresponding function, which can trigger remote command execution."
The researchers who discovered the flaw briefly published a proof-of-concept (PoC) exploit on GitHub, but later retracted it.
Akamai's observations show attackers are sending POST requests that
2025-03-25
Published
2026-04-24
Added to CISA KEV
Exploited in the wild