Executive brief
A command injection vulnerability exists in D-Link DIR-823X routers, which are networking devices used to provide internet connectivity. An attacker with administrative access can take complete control of the device to execute unauthorized commands, potentially leading to data interception or using the device as a foothold for further attacks. This vulnerability is currently being exploited in the wild, and because the product may be at its end-of-life, users are advised to replace the hardware.
Technical details
A command injection vulnerability (CWE-77) exists in the D-Link DIR-823X router firmware versions 240126 and 240802. The flaw is located within the handling of POST requests to the /goform/set_prohibiting endpoint, where unsanitized input is passed to a system shell. An attacker with high privileges (administrative access) can exploit this over the network to achieve remote code execution (RCE) on the underlying operating system. This vulnerability has been observed in active exploitation, notably by Mirai-based botnets. As the device is potentially End-of-Life (EoL), no official patch may be available, and CISA recommends discontinuing use.
Affected products
- D-Link DIR-823X firmware 240126, 240802
Timeline
- 2025-03-25: disclosed: Initial CVE publication
- 2026-04-24: kev added: CISA added to Known Exploited Vulnerabilities catalog due to Mirai campaign activity
- 2026-04-24: exploited: Reports of active exploitation in Mirai botnet campaigns