Description
A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Problem types
Product status
Timeline
| 2025-12-07: | Advisory disclosed |
| 2025-12-07: | VulDB entry created |
| 2025-12-07: | VulDB entry last update |
Credits
panda_0x1 (VulDB User)
References
vuldb.com/?id.334651 (VDB-334651 | D-Link DIR-823X set_wan_settings sub_415028 command injection)
vuldb.com/?ctiid.334651 (VDB-334651 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.700499 (Submit #700499 | D-Link DIR-823X 250416 Command Injection)
github.com/.../blob/main/d-link/dir-823x/set_wan_settings.md
github.com/.../blob/main/d-link/dir-823x/set_wan_settings.md
www.dlink.com/