A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
Tue, 25 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-03-25T00:00:00.000Z
Updated: 2025-03-25T14:50:51.121Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29635
Updated: 2025-03-25T14:49:53.234Z
Status : Analyzed
Published: 2025-03-25T14:15:29.043
Modified: 2025-04-03T17:35:51.163
Link: CVE-2025-29635
No data.