← Vulnerability feed

Vulnerability record · CVE-2026-2084 · published 7 February 2026

CVE-2026-2084: Dlink dir-823x firmware command injection vulnerability

Dlink · Dir 823x Firmware

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

7.3 CVSS 4.0 High EPSS 4.1% · top 9.6% CWE-77 · Command injectionCWE-78 · OS command injection
7.3CVSS 4.0 base score, v2 8.3
4.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_language. Executing a manipulation of the argument langSelection can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/master-abc/cve/issues/24 ExploitIssue Tracking
https://vuldb.com/?ctiid.344651 Permissions RequiredVDB Entry
https://vuldb.com/?id.344651 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.746379 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.746380 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product

Track CVE-2026-2084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed9.8CVE-2025-29042Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232cEPSS 2.3%9.8CVE-2025-29043Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%9.8CVE-2025-29040Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%9.8CVE-2025-29041Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710cEPSS 1.4%9.8CVE-2024-39962Dlink dir-823x firmware code injection vulnerabilityD-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp…EPSS 2.1%8.8CVE-2025-55848Dlink dir-823x firmware command injection vulnerabilityAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame…EPSS 0.41%8.7CVE-2025-0492Dlink dir-823x firmware improper resource shutdown vulnerabilityA vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_004122…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2026-2084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.