← Vulnerability feed

Vulnerability record · CVE-2025-29635 · published 25 March 2025

CVE-2025-29635: D-Link DIR-823X command injection in set_prohibiting handler

Dlink · Dir 823x Firmware

D-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already holds valid credentials can inject and execute arbitrary commands on the device. Because the device is internet-facing in many deployments, successful exploitation gives full control of the router.

7.2 CVSS 3.1 High CISA KEV since 24 Apr 2026 EPSS 88% · top 0.2% CWE-77 · Command injection
7.2CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is confirmed exploited in the wild, listed in CISA KEV with a near-term due date, and carries a very high EPSS score, making it an urgent patching priority.

What it is

D-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already holds valid credentials can inject and execute arbitrary commands on the device. Because the device is internet-facing in many deployments, successful exploitation gives full control of the router.

Impact

An authenticated attacker gains arbitrary command execution on the device, allowing full compromise of the router, traffic interception or redirection, and use of the device as a foothold into the network.

Attack surface

Reached remotely over the network via an HTTP POST to /goform/set_prohibiting. The CVSS vector (PR:H) indicates valid credentials are required; no user interaction is needed.

Exploitation

CVE-2025-29635 is listed in CISA KEV with a 2026-05-08 remediation due date, and EPSS shows a 30-day probability of roughly 0.88 (99.8th percentile). References include exploit write-ups and an Akamai report describing a Mirai campaign targeting D-Link devices, so active exploitation is confirmed.

What to do

  • Apply the vendor's patched firmware for DIR-823X; if no fix is available, discontinue use or replace the device per CISA KEV guidance.
  • Remove or restrict internet exposure of the router's management interface; block external access to /goform/ endpoints.
  • Change default and weak administrative credentials and enforce strong unique passwords, since exploitation requires authentication.
  • Segment IoT and router management traffic from trusted internal networks to limit lateral movement if the device is compromised.
  • Monitor vendor advisories and CISA KEV for updated remediation deadlines and replacement guidance.

Detection

  • Inspect HTTP logs for POST requests to /goform/set_prohibiting, especially from unexpected or external source IPs.
  • Alert on shell metacharacters or command strings in parameters sent to /goform/set_prohibiting.
  • Monitor router outbound traffic for connections to known Mirai C2 infrastructure or unusual scanning behavior.
  • Watch for unexpected processes, cron entries, or configuration changes on the device that indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-29635 to the Known Exploited Vulnerabilities catalog on 24 April 2026 as "D-Link DIR-823X Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-29635 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-29042Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232cEPSS 2.3%9.8CVE-2025-29043Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%9.8CVE-2025-29040Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%9.8CVE-2025-29041Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710cEPSS 1.4%9.8CVE-2024-39962Dlink dir-823x firmware code injection vulnerabilityD-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp…EPSS 2.1%8.8CVE-2025-55848Dlink dir-823x firmware command injection vulnerabilityAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame…EPSS 0.41%8.7CVE-2025-0492Dlink dir-823x firmware improper resource shutdown vulnerabilityA vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_004122…EPSS 1.9%7.3CVE-2026-2210Dlink dir-823x firmware command injection vulnerabilityA vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation l…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2025-29635), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.