CVE-2025-29635

9.5 CISA KEV

D-Link · DIR-823X

A command injection vulnerability in D-Link DIR-823X firmware allows authorized attackers to execute arbitrary system commands via a POST request to the set_prohibiting function.

Executive summary

A critical command injection vulnerability in legacy D-Link DIR-823X routers is being actively exploited in the wild to recruit devices into a DDoS botnet.

Vulnerability

The vulnerability exists because attacker-controlled input is passed to the system() function without sanitization, allowing shell metacharacter injection. While the CVSS vector indicates high privileges are required, the vulnerability is being actively exploited in the wild.

Business impact

The exploitation of this flaw allows attackers to execute arbitrary code on the affected router with system-level privileges. This poses a severe risk of total device compromise, potential inclusion in botnets for distributed denial of service attacks, and lateral movement into the local network. Given the CVSS score of 9.5, this vulnerability represents a critical security risk to any organization still utilizing these legacy devices.

Remediation

Immediate Action: As these devices are discontinued and vulnerable, the primary recommendation is to decommission and replace the affected hardware immediately.

Proactive Monitoring: Monitor network traffic for anomalous outbound connections, particularly those associated with Mirai botnet command and control signatures.

Compensating Controls: If immediate removal is not possible, place the devices on an isolated management network and restrict access to the web interface to authorized internal IP addresses only.

Exploitation status

Public Exploit Available: Yes (Nuclei detection template exists).

Analyst recommendation

Due to the critical nature of this vulnerability and the observed active exploitation in the wild, immediate action is required. Organizations should prioritize the retirement of these end-of-life D-Link devices to eliminate the risk of continued compromise and potential network disruption.

More D-Link CVEs

Sources