VYPR
Unrated severityNVD Advisory· Published Feb 7, 2026· Updated Feb 23, 2026

D-Link DIR-823X set_language os command injection

CVE-2026-2084

Description

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

2
  • Dlink/DIR-823Gllm-fuzzy
    Range: = 250416
  • D-Link/DIR-823Xv5
    Range: 250416

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.