VendorsD-Linkdir-823x_firmware240126
Vulnerabilities

D-Link dir-823x Firmware 240126

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-39962
D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.
Published 2024-07-19 · Analyzed
9.8EPSS 0.021
CVE-2025-10634
D-Link DIR-823X Environment Variable goahead sub_412E7C command injection
Published 2025-09-18 · Analyzed
8.8EPSS 0.074
CVE-2025-10814
D-Link DIR-823X goahead command injection
Published 2025-09-22 · Analyzed
8.8EPSS 0.061
CVE-2025-0492
D-Link DIR-823X FUN_00412244 null pointer dereference
Published 2025-01-15 · Analyzed
8.7EPSS 0.019
CVE-2025-29635
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Published 2025-03-25 · Analyzed
7.2KEVEPSS 0.879
CVE-2025-2717
D-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injection
Published 2025-03-24 · Analyzed
7.2EPSS 0.045
CVE-2025-1103
D-Link DIR-823X HTTP POST Request set_wifi_blacklists null pointer dereference
Published 2025-02-07 · Analyzed
7.1EPSS 0.141