CVE-2026-2210
7.2D-Link · DIR-823X
A remote OS command injection vulnerability exists in the D-Link DIR-823X firmware version 250416 via the set_filtering function.
Executive summary
A critical OS command injection vulnerability in D-Link DIR-823X allows remote attackers to execute arbitrary commands with high privileges.
Vulnerability
The device is susceptible to OS command injection within the sub_4211C8 function of the /goform/set_filtering endpoint. While the CVSS vector indicates that high privileges are required for exploitation, the vulnerability is reachable remotely and allows for complete system compromise.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary system commands on the affected router. This can lead to total device takeover, interception of network traffic, and persistence within the local network environment, posing a significant risk to data confidentiality and network integrity. The CVSS score of 7.2 reflects the high potential for impact despite the requirement for administrative authentication.
Remediation
Immediate Action: There is currently no official patch available from the vendor. Administrators should immediately restrict access to the web management interface to trusted internal networks only and disable remote management features.
Proactive Monitoring: Monitor device access logs for unusual patterns or attempts to access the /goform/set_filtering endpoint. Watch for unexpected outbound network traffic originating from the router that may indicate command and control activity.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block malicious payloads targeting the /goform/set_filtering parameter.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via a published researcher write-up on GitHub.
Analyst recommendation
Given the availability of a public proof-of-concept and the high potential for full system compromise, this vulnerability poses a significant risk to affected D-Link environments. Organizations should prioritize isolating these devices from external networks and remain vigilant for vendor-provided firmware updates. Until a patch is released, strict network segmentation remains the most effective defense against remote exploitation.
More D-Link CVEs
Sources
Originally found and disclosed by junqi (VulDB User), per the CVE Program record.
- VDB-344925 | D-Link DIR-823X set_filtering sub_4211C8 os command injection Vulnerability database entry
- VDB-344925 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #752165 | D-Link DIR-823X 250416 OS Command Injection Third-party advisory
- Issue tracker
- Exploit / PoC
- dlink.com