D-Link DIR-823X Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in versions through 250416. The issue arises in the '/goform/diag_ping' file, where the 'target_addr' parameter is not properly validated. This lack of validation allows attackers to inject malicious commands, which can be executed on the device. The vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, log into the router and navigate to the '/goform/diag_ping' endpoint. The 'target_addr' parameter can be manipulated by injecting commands, such as using a semicolon to separate commands. Once the payload is sent, the injected commands will be executed on the router's operating system.

Added: Sep 14, 2025, 4:17 PM
Updated: Sep 14, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.