CVE-2026-4193
7.3D-Link · DIR-823G
A vulnerability in the goahead component of D-Link DIR-823G 1.0.2B05 allows remote, unauthenticated attackers to bypass access controls via multiple functions.
Executive summary
A critical access control vulnerability in the D-Link DIR-823G router allows unauthenticated remote attackers to manipulate device settings and potentially compromise system integrity.
Vulnerability
The vulnerability exists within the goahead web server component, where improper access controls in numerous administrative functions allow unauthenticated remote attackers to modify device configurations. This flaw stems from improper privilege assignment, enabling unauthorized access to sensitive router management settings.
Business impact
The ability for an unauthenticated attacker to remotely modify router settings presents a significant risk to network security, potentially leading to unauthorized traffic interception, configuration tampering, or complete loss of network control. With a CVSS score of 7.3, this high-severity vulnerability warrants immediate attention to prevent unauthorized access to internal network infrastructure.
Remediation
Immediate Action: As the affected device is no longer supported by the vendor, the most effective remediation is to retire the hardware and replace it with a supported model.
Proactive Monitoring: Monitor network traffic for unusual administrative requests or unauthorized changes to router configuration parameters.
Compensating Controls: If immediate replacement is not feasible, isolate the device from the public internet using a firewall and disable remote management interfaces to prevent external access.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the VulDB references.
Analyst recommendation
Given that D-Link no longer provides security updates for the DIR-823G, this device is effectively in an end-of-life state and poses a permanent security risk to any network where it remains deployed. Organizations must prioritize the decommissioning of this hardware to eliminate the risk of remote configuration hijacking.
More D-Link CVEs
Sources
Originally found and disclosed by pjqwudi (VulDB User), per the CVE Program record.
- VDB-351105 | D-Link DIR-823G goahead UpdateClientInfo access control Vulnerability database entry
- VDB-351105 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #769835 | D-Link 1.0.2B05 Improper Access Controls Third-party advisory
- Submit #769836 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate) Third-party advisory
- Submit #769837 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate) Third-party advisory
- Submit #769838 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate) Third-party advisory
- Submit #769839 | D-Link DIR823G 1.0.2B05 Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Submit #769841 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate) Third-party advisory