CVE-2026-2143
7.2D-Link · DIR-823X
A command injection vulnerability in the D-Link DIR-823X DDNS service allows remote attackers to execute arbitrary OS commands via the /goform/set_ddns endpoint.
Executive summary
A critical OS command injection vulnerability in D-Link DIR-823X firmware enables remote attackers to compromise the device, presenting a significant security risk.
Vulnerability
The flaw exists within the DDNS service processing of the /goform/set_ddns endpoint, specifically through the manipulation of parameters like ddnsType, ddnsDomainName, ddnsUserName, or ddnsPwd. While the CVSS vector indicates that high privileges are required, the vulnerability allows for remote OS command injection, which can lead to complete device takeover.
Business impact
The ability to execute arbitrary OS commands on a network device allows an attacker to gain full administrative control, potentially leading to unauthorized network access, data interception, or the use of the device in botnet activities. Given the CVSS score of 7.2, this vulnerability represents a high-severity risk that could compromise the integrity and availability of the local network infrastructure.
Remediation
Immediate Action: Since no official patch is currently listed, users should restrict administrative access to the device management interface to trusted IP addresses only and disable the DDNS service if it is not required for network operations.
Proactive Monitoring: Security teams should monitor network traffic for suspicious activity originating from the device and review system logs for unusual process execution or unauthorized configuration changes.
Compensating Controls: Deploy a Web Application Firewall (WAF) or intrusion detection system rules to block malicious payloads directed at the /goform/set_ddns endpoint.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the research write-up hosted on GitHub.
Analyst recommendation
The presence of a public proof-of-concept significantly elevates the risk of exploitation for this device. Administrators must prioritize isolating affected D-Link DIR-823X units from the public internet and monitoring vendor communications for the release of a security firmware update.
More D-Link CVEs
Sources
Originally found and disclosed by jiefengliang (VulDB User), per the CVE Program record.
- VDB-344778 | D-Link DIR-823X DDNS Service set_ddns os command injection Vulnerability database entry
- VDB-344778 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #747492 | D-Link DIR-823X 250416 OS Command Injection Third-party advisory
- Exploit / PoC
- dlink.com