CVE-2026-2084
7.2D-Link · DIR-823X
D-Link DIR-823X firmware version 250416 is susceptible to remote OS command injection via the langSelection argument in the /goform/set_language endpoint.
Executive summary
A critical OS command injection vulnerability in D-Link DIR-823X firmware allows remote attackers with administrative privileges to execute arbitrary system commands.
Vulnerability
The vulnerability exists in the /goform/set_language endpoint due to improper neutralization of special elements in the langSelection argument. This flaw allows a remote, authenticated attacker with administrative privileges to achieve OS command injection.
Business impact
Successful exploitation grants an attacker the ability to execute arbitrary commands on the underlying operating system of the router. Given the CVSS score of 7.2, this represents a significant risk, as it can lead to full device compromise, persistent backdoor installation, and the potential for lateral movement within the internal network.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict management interface access to trusted internal networks only and disable remote administration features until the vendor releases a firmware update.
Proactive Monitoring: Monitor device logs for unusual activity originating from the /goform/set_language endpoint and watch for unauthorized configuration changes or unexpected outbound network traffic from the router.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule specifically configured to inspect and block malicious payloads targeting the langSelection parameter in HTTP requests.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher at the referenced GitHub repository.
Analyst recommendation
Given the availability of a public proof-of-concept and the high potential impact on network integrity, this vulnerability poses a credible threat to organizations utilizing this D-Link hardware. Security teams must prioritize isolating affected devices from public internet exposure and should maintain close contact with the vendor for the release of a security patch.
More D-Link CVEs
Sources
Originally found and disclosed by 942384053 (VulDB User), per the CVE Program record.
- VDB-344651 | D-Link DIR-823X set_language os command injection Vulnerability database entry
- VDB-344651 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #746379 | D-Link DIR 250416 OS Command Injection Third-party advisory
- Submit #746380 | D-Link DIR-823X 250416 OS Command Injection (Duplicate) Third-party advisory
- Exploit / PoC
- dlink.com