← Vulnerability feed

Vulnerability record · CVE-2026-2155 · published 8 February 2026

CVE-2026-2155: Dlink dir-823x firmware command injection vulnerability

Dlink · Dir 823x Firmware

A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

7.3 CVSS 4.0 High EPSS 4.0% · top 9.9% CWE-77 · Command injectionCWE-78 · OS command injection
7.3CVSS 4.0 base score, v2 8.3
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/master-abc/cve/issues/32 ExploitIssue Tracking
https://vuldb.com/?ctiid.344857 Permissions RequiredVDB Entry
https://vuldb.com/?id.344857 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.748236 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.750038 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product

Track CVE-2026-2155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed9.8CVE-2025-29042Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232cEPSS 2.3%9.8CVE-2025-29043Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234EPSS 1.8%9.8CVE-2025-29040Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%9.8CVE-2025-29041Dlink dir-823x firmware os command injection vulnerabilityAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710cEPSS 1.4%9.8CVE-2024-39962Dlink dir-823x firmware code injection vulnerabilityD-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp…EPSS 2.1%8.8CVE-2025-55848Dlink dir-823x firmware command injection vulnerabilityAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parame…EPSS 0.41%8.7CVE-2025-0492Dlink dir-823x firmware improper resource shutdown vulnerabilityA vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_004122…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2026-2155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.