CVE-2026-2175
7.2D-Link · DIR-823X
D-Link DIR-823X version 250416 is vulnerable to OS command injection via the upnp_enable argument in the /goform/set_upnp endpoint.
Executive summary
An OS command injection vulnerability in the D-Link DIR-823X router allows an authenticated attacker to execute arbitrary system commands, posing a critical risk to network integrity.
Vulnerability
This is an OS command injection vulnerability (CWE-78) located in the sub_420618 function within the /goform/set_upnp file. Attackers with high privileges can manipulate the upnp_enable argument to execute unauthorized system commands.
Business impact
The ability to execute arbitrary OS commands on a network device grants an attacker complete control over the compromised hardware. This could lead to full network interception, unauthorized access to internal resources, or the use of the router as a pivot point for further lateral movement within the business environment. Given the CVSS score of 7.2, this vulnerability represents a significant risk to organizational infrastructure and data confidentiality.
Remediation
Immediate Action: Contact D-Link support or monitor the official D-Link security portal for the release of a firmware update addressing this specific command injection flaw.
Proactive Monitoring: Review device access logs for unusual administrative activity and monitor for unauthorized changes to UPNP configurations or suspicious outbound traffic originating from the router.
Compensating Controls: Restrict administrative access to the router interface to trusted management IP addresses only and disable UPNP functionality if it is not strictly required for business operations.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided via the GitHub reference.
Analyst recommendation
The presence of a public proof-of-concept elevates the risk of this vulnerability significantly. Network administrators should audit all D-Link DIR-823X deployments immediately and ensure that administrative interfaces are not exposed to the public internet. Apply any forthcoming vendor patches as a priority to eliminate the underlying command injection flaw.
More D-Link CVEs
Sources
Originally found and disclosed by jiefengliang (VulDB User), per the CVE Program record.
- VDB-344876 | D-Link DIR-823X set_upnp sub_420618 os command injection Vulnerability database entry
- VDB-344876 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #749263 | D-Link DIR-823X 250416 OS Command Injection Third-party advisory
- Exploit / PoC
- dlink.com