VendorsD-Linkdir-823gall versions
Vulnerabilities

D-Link DIR-823G

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2019-7297
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.
Published 2019-01-31 · Modified
10.0EPSS 0.125
CVE-2023-26613
An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.
Published 2023-06-29 · Modified
9.8EPSS 0.314
CVE-2025-2359
D-Link DIR-823G DDNS Service HNAP1 SetDDNSSettings improper authorization
Published 2025-03-17 · Analyzed
9.8EPSS 0.154
CVE-2020-25367
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
Published 2021-11-04 · Modified
9.8EPSS 0.086
CVE-2020-25368
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
Published 2021-11-04 · Modified
9.8EPSS 0.086
CVE-2025-2360
D-Link DIR-823G UPnP Service HNAP1 SetUpnpSettings improper authorization
Published 2025-03-17 · Analyzed
9.8EPSS 0.041
CVE-2018-17786
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.
Published 2018-10-02 · Modified
9.8EPSS 0.041
CVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.
Published 2022-11-22 · Modified
9.8EPSS 0.038
CVE-2022-43109
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
Published 2022-11-03 · Modified
9.8EPSS 0.037
CVE-2018-17787
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
Published 2018-10-02 · Modified
9.8EPSS 0.037
CVE-2021-43474
An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
Published 2022-04-07 · Modified
9.8EPSS 0.031
CVE-2024-13030
D-Link DIR-823G Web Management Interface HNAP1 SetVirtualServerSettings access control
Published 2024-12-30 · Analyzed
9.8EPSS 0.019
CVE-2018-17881
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.
Published 2018-10-03 · Modified
9.8EPSS 0.015
CVE-2023-26616
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
Published 2023-06-29 · Modified
9.8EPSS 0.013
CVE-2023-26612
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
Published 2023-06-29 · Modified
9.8EPSS 0.013
CVE-2023-43235
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.
Published 2023-09-21 · Modified
9.8EPSS 0.013
CVE-2023-43241
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
Published 2023-09-21 · Modified
9.8EPSS 0.013
CVE-2022-44201
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
Published 2022-11-22 · Modified
9.8EPSS 0.013
CVE-2023-29665
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
Published 2023-04-17 · Modified
9.8EPSS 0.012
CVE-2019-7298
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body, such as a body of ' /bin/telnetd' for the GetDeviceSettingsset API function. Consequently, an attacker can execute any command remotely when they control this input.
Published 2019-02-01 · Modified
9.3EPSS 0.101
CVE-2020-25366
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
Published 2021-11-04 · Modified
9.1EPSS 0.025
CVE-2019-15529
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
Published 2019-08-23 · Modified
9.0EPSS 0.077
CVE-2019-13128
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
Published 2019-07-01 · Modified
9.0EPSS 0.077
CVE-2019-15530
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
Published 2019-08-23 · Modified
9.0EPSS 0.043
CVE-2019-15528
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2019-15526
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2019-15527
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2024-51023
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
Published 2024-11-05 · Analyzed
8.8EPSS 0.015
CVE-2024-27655
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.012
CVE-2024-27657
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.012
CVE-2024-27656
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.006
CVE-2026-11492
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
Published 2026-06-08 · Analyzed
8.8EPSS 0.005
CVE-2019-7390
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.
Published 2019-02-05 · Modified
8.6EPSS 0.020
CVE-2024-51024
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
Published 2024-11-05 · Analyzed
8.0EPSS 0.014
CVE-2019-7389
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a denial-of-service attack without authentication.
Published 2019-02-05 · Modified
7.8EPSS 0.027
CVE-2018-17880
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot.
Published 2018-10-03 · Modified
7.8EPSS 0.016
CVE-2023-44839
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.081
CVE-2025-60332
A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.050
CVE-2019-7388
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.
Published 2019-02-05 · Modified
7.5EPSS 0.028
CVE-2019-8392
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.
Published 2019-02-17 · Modified
7.5EPSS 0.022
1 / 2Next →