A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-25T00:00:00.000Z
Updated: 2025-03-25T14:50:51.121Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29635

Updated: 2025-03-25T14:49:53.234Z

Status : Received
Published: 2025-03-25T14:15:29.043
Modified: 2025-03-25T15:15:25.443
Link: CVE-2025-29635

No data.