D-Link Dir-823X vulnerabilities

31 known vulnerabilities affecting d-link/dir-823x.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM20

Vulnerabilities

Page 2 of 2
CVE-2025-11092MEDIUMCVSS 5.3v2504162025-09-28
CVE-2025-11092 [MEDIUM] CWE-74 CVE-2025-11092: A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_switch_settings. This manipulation of the argument port causes command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
cvelistv5nvd
CVE-2025-11099MEDIUMCVSS 5.3v2504162025-09-28
CVE-2025-11099 [MEDIUM] CWE-74 CVE-2025-11099: A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_d A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
cvelistv5nvd
CVE-2025-11095MEDIUMCVSS 5.3v2504162025-09-28
CVE-2025-11095 [MEDIUM] CWE-74 CVE-2025-11095: A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of t A vulnerability was detected in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing manipulation of the argument delvalue results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
cvelistv5nvd
CVE-2025-11098MEDIUMCVSS 5.3v2504162025-09-28
CVE-2025-11098 [MEDIUM] CWE-74 CVE-2025-11098: A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.
cvelistv5nvd
CVE-2025-10814MEDIUMCVSS 5.3v240126v240802+1 more2025-09-22
CVE-2025-10814 [MEDIUM] CWE-74 CVE-2025-10814: A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerabili A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
cvelistv5nvd
CVE-2025-10634MEDIUMCVSS 5.3v240126v240802+1 more2025-09-18
CVE-2025-10634 [MEDIUM] CWE-74 CVE-2025-10634: A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been m
cvelistv5nvd
CVE-2025-10401MEDIUMCVSS 5.3v2504162025-09-14
CVE-2025-10401 [MEDIUM] CWE-74 CVE-2025-10401: A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown fun A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
cvelistv5nvd
CVE-2025-10123MEDIUMCVSS 6.9v2504162025-09-09
CVE-2025-10123 [MEDIUM] CWE-74 CVE-2025-10123: A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is th A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
cvelistv5nvd
CVE-2025-2717MEDIUMCVSS 5.1v240126v2408022025-03-25
CVE-2025-2717 [MEDIUM] CWE-77 CVE-2025-2717: A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os command injection. The attack may be initiated remotely. The exploit has been
cvelistv5nvd
CVE-2025-1103HIGHCVSS 7.1v240126v2408022025-02-07
CVE-2025-1103 [HIGH] CWE-404 CVE-2025-1103: A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. Th A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of the file /goform/set_wifi_blacklists of the component HTTP POST Request Handler. The manipulation of the argument macList leads to null pointer dereference. It is possible to initiate the attack remotely. The
cvelistv5nvd
CVE-2025-0492HIGHCVSS 8.7v240126v2408022025-01-15
CVE-2025-0492 [HIGH] CWE-404 CVE-2025-0492: A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd