cbcvebase.

Dlink Dir-823G Firmware vulnerabilities

59 known vulnerabilities affecting dlink/dir-823g_firmware.

Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL16HIGH35MEDIUM8

Vulnerabilities

Page 1 of 3
CVE-2024-13030P1CRITICALCVSS 9.8Exploitedv1.0.2b05_201812072024-12-30
CVE-2024-13030 [CRITICAL] CWE-266 CVE-2024-13030: A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of the component Web Management Interface. The manipulation leads to i
nvd
CVE-2023-26613P1CRITICALCVSS 9.8v1.02b052023-06-29
CVE-2023-26613 [CRITICAL] CWE-78 CVE-2023-26613: An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorize An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.
nvd
CVE-2025-2359P2CRITICALCVSS 9.8v1.0.2b05_201812072025-03-17
CVE-2025-2359 [CRITICAL] CWE-266 CVE-2025-2359: A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public
nvd
CVE-2022-44808P2CRITICALCVSS 9.8v1.02b032022-11-22
CVE-2022-44808 [CRITICAL] CWE-78 CVE-2022-44808: A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1. A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerabilit
nvd
CVE-2025-2360P2CRITICALCVSS 9.8v1.0.2b05_201812072025-03-17
CVE-2025-2360 [CRITICAL] CWE-266 CVE-2025-2360: A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by t A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to th
nvd
CVE-2022-43109P2CRITICALCVSS 9.8v1.0.22022-11-03
CVE-2022-43109 [CRITICAL] CWE-77 CVE-2022-43109: D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNet D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
nvd
CVE-2020-25367P2CRITICALCVSS 9.8v1.0.2b052021-11-04
CVE-2020-25367 [CRITICAL] CWE-78 CVE-2020-25367: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices wi A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
nvd
CVE-2020-25368P2CRITICALCVSS 9.8v1.02b052021-11-04
CVE-2020-25368 [CRITICAL] CWE-78 CVE-2020-25368: A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices wi A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
nvd
CVE-2019-13128P2HIGHCVSS 8.8v1.02b032019-07-01
CVE-2019-13128 [HIGH] CWE-78 CVE-2019-13128: An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injecti An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
nvd
CVE-2019-7298P2HIGHCVSS 8.1≤ 1.02b032019-02-01
CVE-2019-7298 [HIGH] CWE-78 CVE-2019-7298: An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injectio An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body, such as a body of ' /bin/telnetd' for
nvd
CVE-2026-11492P2HIGHCVSS 8.8v1.0.2b052026-06-08
CVE-2026-11492 [HIGH] CWE-266 CVE-2026-11492: A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2021-43474P3CRITICALCVSS 9.8v1.02b052022-04-07
CVE-2021-43474 [CRITICAL] CWE-77 CVE-2021-43474: An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
nvd
CVE-2019-15529P3HIGHCVSS 8.8v1.0.2b052019-08-23
CVE-2019-15529 [HIGH] CWE-78 CVE-2019-15529: An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injec An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
nvd
CVE-2023-43241P3CRITICALCVSS 9.8v1.0.2b052023-09-21
CVE-2023-43241 [CRITICAL] CWE-787 CVE-2023-43241: D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and Guard D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
nvd
CVE-2023-43235P3CRITICALCVSS 9.8v1.0.2b052023-09-21
CVE-2023-43235 [CRITICAL] CWE-787 CVE-2023-43235: D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and End D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.
nvd
CVE-2024-51023P3HIGHCVSS 8.8v1.0.2b052024-11-05
CVE-2024-51023 [HIGH] CWE-78 CVE-2024-51023: D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
nvd
CVE-2019-15530P3HIGHCVSS 8.8v1.0.2b052019-08-23
CVE-2019-15530 [HIGH] CWE-78 CVE-2019-15530: An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injec An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
nvd
CVE-2019-15527P3HIGHCVSS 8.8v1.0.2b052019-08-23
CVE-2019-15527 [HIGH] CWE-78 CVE-2019-15527: An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injec An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.
nvd
CVE-2019-15528P3HIGHCVSS 8.8v1.0.2b052019-08-23
CVE-2019-15528 [HIGH] CWE-78 CVE-2019-15528: An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injec An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
nvd
CVE-2023-29665P3CRITICALCVSS 9.8v1.0.2b052023-04-17
CVE-2023-29665 [CRITICAL] CWE-787 CVE-2023-29665: D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters i D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
nvd
Dlink Dir-823G Firmware vulnerabilities | cvebase