Dlink Dir-823G Firmware vulnerabilities
59 known vulnerabilities affecting dlink/dir-823g_firmware.
Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL16HIGH35MEDIUM8
Vulnerabilities
Page 2 of 3
CVE-2019-7390P3HIGHCVSS 8.6v1.02b032019-02-05
CVE-2019-7390 [HIGH] CWE-306 CVE-2019-7390: An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is i
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.
nvd
CVE-2019-15526P3HIGHCVSS 8.8v1.0.2b052019-08-23
CVE-2019-15526 [HIGH] CVE-2019-15526: An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injec
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
nvd
CVE-2026-4193P3HIGHCVSS 7.5v1.0.2b052026-03-16
CVE-2026-4193 [HIGH] CWE-266 CVE-2026-4193: A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the
A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/GetRouterInformationSettings/GetRouterLanSettings/GetWanSet
nvd
CVE-2026-15270P3HIGHCVSS 7.5v1.0.2b05_201812072026-07-09
CVE-2026-15270 [HIGH] CWE-266 CVE-2026-15270: A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitatio
nvd
CVE-2024-51024P3HIGHCVSS 8.0v1.0.2b052024-11-05
CVE-2024-51024 [HIGH] CWE-78 CVE-2024-51024: D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostNam
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
nvd
CVE-2023-26616P3CRITICALCVSS 9.8v1.02b052023-06-29
CVE-2023-26616 [CRITICAL] CWE-120 CVE-2023-26616: D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
nvd
CVE-2023-26612P3CRITICALCVSS 9.8v1.02b052023-06-29
CVE-2023-26612 [CRITICAL] CWE-120 CVE-2023-26612: D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
nvd
CVE-2022-44201P3CRITICALCVSS 9.8v1.02b052022-11-22
CVE-2022-44201 [CRITICAL] CWE-78 CVE-2022-44201: D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
nvd
CVE-2019-7389P3HIGHCVSS 7.5v1.02b032019-02-05
CVE-2019-7389 [HIGH] CWE-306 CVE-2019-7389: An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a denial-of-service attack without authentication.
nvd
CVE-2024-27655P3HIGHCVSS 8.8v1.0.2b052024-02-29
CVE-2024-27655 [HIGH] CWE-121 CVE-2024-27655: D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
nvd
CVE-2019-8392P3HIGHCVSS 7.5v1.02b032019-02-17
CVE-2019-8392 [HIGH] CVE-2019-8392: An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.
nvd
CVE-2025-60675P3MEDIUMCVSS 5.4v1.0.2b05_201812072025-11-13
CVE-2025-60675 [MEDIUM] CWE-77 CVE-2025-60675: A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20
A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command strings and executed via system() witho
nvd
CVE-2024-27657P3HIGHCVSS 8.8v1.0.2b052024-02-29
CVE-2024-27657 [HIGH] CWE-121 CVE-2024-27657: D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
nvd
CVE-2024-27656P3HIGHCVSS 8.8v1.0.2b052024-02-29
CVE-2024-27656 [HIGH] CWE-121 CVE-2024-27656: D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. Th
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
nvd
CVE-2019-7388P3HIGHCVSS 7.5v1.02b032019-02-05
CVE-2019-7388 [HIGH] CWE-200 CVE-2019-7388: An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is i
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.
nvd
CVE-2025-60671P3MEDIUMCVSS 5.4v1.0.2b05_201812072025-11-13
CVE-2025-60671 [MEDIUM] CWE-77 CVE-2025-60671: A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20
A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only partially validated for a prefix and then formatted using vsnprintf() before
nvd
CVE-2023-44839P3HIGHCVSS 7.5v1.0.2b052023-10-05
CVE-2023-44839 [HIGH] CWE-120 CVE-2023-44839: D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2020-25366P3CRITICALCVSS 9.1v1.02b052021-11-04
CVE-2020-25366 [CRITICAL] CWE-862 CVE-2020-25366: An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attac
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
nvd
CVE-2023-26615P3HIGHCVSS 7.5v1.02b052023-06-28
CVE-2023-26615 [HIGH] CWE-640 CVE-2023-26615: D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from t
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
nvd
CVE-2025-60332P3HIGHCVSS 7.5v1.0.2b052025-10-22
CVE-2025-60332 [HIGH] CWE-476 CVE-2025-60332: A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allo
A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
nvd