Executive brief
A security vulnerability exists in the D-Link DIR-823G, a wireless router used for home and small office internet connectivity. The device fails to properly check data within its internal configuration files, which could allow an attacker who has gained a foothold on the device to take full control of the system. This could lead to the interception of network traffic, unauthorized access to connected devices, or a complete disruption of internet services.
Technical details
A command injection vulnerability exists in the 'timelycheck' and 'sysconf' binaries of the D-Link DIR-823G router (firmware version DIR823G_V1.0.2B05_20181207.bin). The issue stems from the improper sanitization of fields parsed from the '/tmp/new_qos.rule' configuration file using sscanf(). These unsanitized strings are subsequently concatenated into iptables command strings and executed via the system() function. An attacker who can modify this temporary file—either through local access or by exploiting other vulnerabilities that allow filesystem writes—can achieve arbitrary code execution with the privileges of the affected binaries. While the CVSS vector suggests a network attack vector with low privileges, the exploit specifically requires the ability to write to the /tmp directory.
Affected products
- D-Link DIR-823G DIR823G_V1.0.2B05_20181207.bin
Timeline
- 2025-11-13: advisory: Initial NVD publication