← Vulnerability feed

Vulnerability record · CVE-2025-29041 · published 17 April 2025

CVE-2025-29041: Dlink dir-823x firmware os command injection vulnerability

Dlink · Dir 823x Firmware

An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

9.8 CVSS 3.1 Critical EPSS 1.4% · top 29.0% CWE-78 · OS command injection
9.8CVSS 3.1 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-29041 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed9.8CVE-2025-29042Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232cEPSS 2.3%9.8CVE-2025-29043Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%9.8CVE-2025-29040Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%9.8CVE-2024-39962Dlink dir-823x firmware code injection vulnerabilityD-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp…EPSS 2.1%8.8CVE-2025-55848Dlink dir-823x firmware command injection vulnerabilityAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame…EPSS 0.41%8.7CVE-2025-0492Dlink dir-823x firmware improper resource shutdown vulnerabilityA vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_004122…EPSS 1.9%7.3CVE-2026-2210Dlink dir-823x firmware command injection vulnerabilityA vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation l…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2025-29041), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.