← Vulnerability feed

Vulnerability record · CVE-2023-49004 · published 19 December 2023

CVE-2023-49004: Dlink dir-850l firmware code injection vulnerability

Dlink · Dir 850l Firmware

An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 21.6% CWE-94 · Code injection
9.8CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49004 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-20675Dlink dir-822 firmware improper authentication vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 1.8%9.8CVE-2016-6563D-Link DIR routers stack buffer overflow via HNAP SOAP loginMalformed SOAP messages sent to the HNAP Login action overflow a stack buffer in several D-Link DIR router models. The vulnerable XML fields are Acti…EPSS 80%analysed9.8CVE-2018-9032Dlink dir-850l firmware improper authentication vulnerabilityAn authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version…EPSS 28%9.8CVE-2017-14417Dlink dir-850l firmware missing authentication for critical function vulnerabilityregister_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintende…EPSS 1.3%9.8CVE-2017-14421Dlink dir-850l firmware hard-coded credentials vulnerabilityD-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks ac…EPSS 2.3%9.8CVE-2017-14429Dlink dir-850l firmware os command injection vulnerabilityThe DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows …EPSS 4.9%8.8CVE-2018-20674Dlink dir-822 firmware vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 2.5%8.8CVE-2017-3193Dlink dir-850l firmware stack-based buffer overflow vulnerabilityMultiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web …EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2023-49004), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.