← back
CVE-2025-29635

CVE-2025-29635

CVSS 7.2 HIGHEPSS 35.4%● KEVCWE-77
Vexday Risk Score
63High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.2EPSS 35.4%KEV simPoC Patch
Lifecycle
25 Mar 2025Published on NVD
24 Apr 2026Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

An authorized user can execute arbitrary commands on D-Link DIR-823X routers by sending a specially crafted request, potentially allowing them to take complete control of the device.

Technical detail

Command injection vulnerability in POST endpoint /goform/set_prohibiting allows authenticated attackers to inject OS commands through unsanitized input parameters. The vulnerability affects D-Link DIR-823X versions 240126 and 240802, resulting in unauthenticated remote code execution with device privileges.

Summary generated and translated by AI from the official description.
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →