Description
A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/GetRouterInformationSettings/GetRouterLanSettings/GetWanSettings/SetAccessCtlList/SetAccessCtlSwitch/SetDeviceSettings/SetGuestWLanSettings/SetIPv4FirewallSettings/SetNetworkSettings/SetNetworkTomographySettings/SetNTPServerSettings/SetRouterLanSettings/SetStaticClientInfo/SetStaticRouteSettings/SetWLanRadioSecurity/SetWPSSettings/UpdateClientInfo of the component goahead. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-03-15: | Advisory disclosed |
| 2026-03-15: | VulDB entry created |
| 2026-03-15: | VulDB entry last update |
Credits
pjqwudi (VulDB User)
References
vuldb.com/?id.351105 (VDB-351105 | D-Link DIR-823G goahead UpdateClientInfo access control)
vuldb.com/?ctiid.351105 (VDB-351105 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.769835 (Submit #769835 | D-Link 1.0.2B05 Improper Access Controls)
vuldb.com/?submit.769836 (Submit #769836 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate))
vuldb.com/?submit.769837 (Submit #769837 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate))
vuldb.com/?submit.769838 (Submit #769838 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate))
vuldb.com/?submit.769839 (Submit #769839 | D-Link DIR823G 1.0.2B05 Stack-based Buffer Overflow (Duplicate))
vuldb.com/?submit.769841 (Submit #769841 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate))
github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_91/91.md
github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_92/92.md
www.dlink.com/