


Perceptive Security
SOC/SIEM Consultancy

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST …
Published:
24 april 2026 om 00:00:00
Alert date:
24 april 2026 om 18:03:40
Source:
cisa.gov
Network Infrastructure, Mobile & IoT
D-Link DIR-823X routers contain a command injection vulnerability (CVE-2025-29635) that allows authorized attackers to execute arbitrary commands remotely. The vulnerability is exploited by sending a POST request to /goform/set_prohibiting endpoint. The affected product may be end-of-life or end-of-service. CISA and D-Link recommend users discontinue product utilization due to the security risk.
Technical details
Mitigation steps:
Affected products:
D-Link DIR-823X
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-29635
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469
Related CVE's:
Related threat actors:
IOC's:
/goform/set_prohibiting
This article was created with the assistance of AI technology by Perceptive.
