📦 Dir 823x Firmware

by Dlink

🔍 What is Dir 823x Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-29042

CRITICAL CVSS 9.8 Apr 17, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-832x routers by injecting malicious code into the macaddr parameter. Attackers can gain full control of affected ...

CVE-2025-29040

CRITICAL CVSS 9.8 Apr 17, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR 823x routers via command injection in the target_addr parameter of the diagnostic ping function. Attackers can ga...

CVE-2024-39962

CRITICAL CVSS 9.8 Jul 19, 2024

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-823X AX3000 routers by sending a specially crafted HTTP request to the ntp_zone_val parameter. Attackers can gain ful...

CVE-2026-2210

HIGH CVSS 7.2 Feb 9, 2026

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by manipulating the set_filtering function, potentiall...

CVE-2026-2175

HIGH CVSS 7.2 Feb 8, 2026

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected devices. The vulnerability exists in the UPnP...

CVE-2026-2157

HIGH CVSS 7.2 Feb 8, 2026

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by manipulating parameters in the static route configu...

CVE-2026-2155

HIGH CVSS 7.2 Feb 8, 2026

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by manipulating the dmz_host/dmz_enable parameters in ...

CVE-2026-2129

HIGH CVSS 7.2 Feb 8, 2026

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected devices. The vulnerability exists in the /gof...

CVE-2026-2120

HIGH CVSS 7.2 Feb 8, 2026

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by manipulating configuration parameters, potentially ...

CVE-2026-1125

HIGH CVSS 7.3 Jan 18, 2026

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary commands by manipulating the wd_enable parameter in the set_wifidog_settings fun...

CVE-2025-55848

HIGH CVSS 8.8 Sep 26, 2025

This vulnerability allows remote command execution on D-Link DIR-823 routers through improper input filtering in the set_cassword settings interface. Attackers can inject reverse shell commands via th...

CVE-2025-10123

HIGH CVSS 7.3 Sep 9, 2025

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands by manipulating the Hostname parameter. The vulnerability aff...

CVE-2025-29039

HIGH CVSS 7.2 Apr 17, 2025

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-832x routers via a specific function (0x41dda8). It affects users of vulnerable D-Link router models with specific fi...

CVE-2025-29635

HIGH CVSS 8.8 Mar 25, 2025

A command injection vulnerability in D-Link DIR-823X routers allows authenticated attackers to execute arbitrary commands on affected devices by sending specially crafted POST requests to the /goform/...

CVE-2025-0492

HIGH CVSS 7.5 Jan 15, 2025

A critical null pointer dereference vulnerability in D-Link DIR-823X routers allows remote attackers to potentially crash the device or execute arbitrary code. This affects users of DIR-823X routers w...

CVE-2026-2063

MEDIUM CVSS 4.7 Feb 6, 2026

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary commands remotely by manipulating the 'ac_server' parameter in the web management i...

CVE-2026-2061

MEDIUM CVSS 4.7 Feb 6, 2026

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers. Attackers can remotely execute arbitrary commands on affected devices by manipulating the set_ipv6 function. This a...

CVE-2026-1544

MEDIUM CVSS 6.3 Jan 28, 2026

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers via the lan_gateway parameter in the /goform/set_mode endpoint. Attackers can execute arbitrary commands remotely wi...

CVE-2025-11100

MEDIUM CVSS 6.3 Sep 28, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by exploiting a command injection flaw in the uci_set function. Attackers can gain unauthorized acce...

CVE-2025-11098

MEDIUM CVSS 6.3 Sep 28, 2025

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected devices. The vulnerability exists in the /goform/...

CVE-2025-11099

MEDIUM CVSS 6.3 Sep 28, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers through command injection in the uci_del function. Attackers can exploit this to gain unauthorized a...

CVE-2025-11097

MEDIUM CVSS 6.3 Sep 28, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by injecting malicious commands into the mac parameter of the /goform/set_device_name endpoint. Atta...

CVE-2025-11096

MEDIUM CVSS 6.3 Sep 28, 2025

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected devices. The vulnerability exists in the /goform/...

CVE-2025-10401

MEDIUM CVSS 6.3 Sep 14, 2025

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823x routers by injecting malicious input into the target_addr parameter of the /goform/diag_ping endpoint. Attac...

CVE-2026-1685

LOW CVSS 3.7 Jan 30, 2026

This vulnerability in D-Link DIR-823X routers allows attackers to bypass authentication attempt limits, potentially enabling brute-force attacks on login credentials. It affects users of specific D-Li...