CVE-2026-2084

7.2

D-Link · DIR-823X

D-Link DIR-823X firmware version 250416 is susceptible to remote OS command injection via the langSelection argument in the /goform/set_language endpoint.

Executive summary

A critical OS command injection vulnerability in D-Link DIR-823X firmware allows remote attackers with administrative privileges to execute arbitrary system commands.

Vulnerability

The vulnerability exists in the /goform/set_language endpoint due to improper neutralization of special elements in the langSelection argument. This flaw allows a remote, authenticated attacker with administrative privileges to achieve OS command injection.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary commands on the underlying operating system of the router. Given the CVSS score of 7.2, this represents a significant risk, as it can lead to full device compromise, persistent backdoor installation, and the potential for lateral movement within the internal network.

Remediation

Immediate Action: Since no official patch is currently identified, administrators should restrict management interface access to trusted internal networks only and disable remote administration features until the vendor releases a firmware update.

Proactive Monitoring: Monitor device logs for unusual activity originating from the /goform/set_language endpoint and watch for unauthorized configuration changes or unexpected outbound network traffic from the router.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule specifically configured to inspect and block malicious payloads targeting the langSelection parameter in HTTP requests.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher at the referenced GitHub repository.

Analyst recommendation

Given the availability of a public proof-of-concept and the high potential impact on network integrity, this vulnerability poses a credible threat to organizations utilizing this D-Link hardware. Security teams must prioritize isolating affected devices from public internet exposure and should maintain close contact with the vendor for the release of a security patch.

More D-Link CVEs

Sources

Originally found and disclosed by 942384053 (VulDB User), per the CVE Program record.