Executive brief
A security flaw exists in the D-Link DIR-823G router, a device used to provide internet connectivity and local networking. An attacker can exploit a configuration error in the file transfer service to gain unauthorized permissions. This could allow a user with low-level access to perform actions they should not be permitted to do, potentially compromising the integrity of files on the device.
Technical details
A least privilege violation (CWE-272) exists in the D-Link DIR-823G firmware version 1.0.2B05. The vulnerability is rooted in the configuration of the vsftpd component, specifically within the /etc/vsftpd.conf file. A remote attacker with low-privileged credentials can manipulate the service to gain unauthorized permissions (Incorrect Privilege Assignment, CWE-266). While the specific function within the configuration file is not identified, the flaw allows for a remote attack vector. Public exploit code has been released, increasing the risk of exploitation.
Affected products
- D-Link DIR-823G 1.0.2B05
Timeline
- 2026-06-08: disclosed: Initial disclosure via VulDB/NVD