VYPR

Dir 823x Firmware

by Dlink

CVEs (104)

  • CVE-2025-29635HigKEVMar 25, 2025
    risk 0.66cvss 7.2epss 0.90

    A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

  • CVE-2023-26613CriJun 29, 2023
    risk 0.66cvss 9.8epss 0.31

    An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

  • CVE-2020-25368CriNov 4, 2021
    risk 0.65cvss 9.8epss 0.09

    A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

  • CVE-2020-25367CriNov 4, 2021
    risk 0.65cvss 9.8epss 0.09

    A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

  • CVE-2019-7297CriJan 31, 2019
    risk 0.65cvss 9.8epss 0.12

    An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function…

  • CVE-2025-29043CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234

  • CVE-2025-29042CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c

  • CVE-2025-29041CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

  • CVE-2025-29040CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c

  • CVE-2024-39962CriJul 19, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.

  • CVE-2023-43241CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.

  • CVE-2023-43235CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

  • CVE-2023-26616CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.

  • CVE-2023-26612CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

  • CVE-2023-29665CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.

  • CVE-2022-44808CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the…

  • CVE-2022-44201CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

  • CVE-2022-43109CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

  • CVE-2021-43474CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.03

    An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

  • CVE-2018-17881CriOct 3, 2018
    risk 0.64cvss 9.8epss 0.01

    On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.

Page 1 of 6