D-Link DIR-823X
cpe:2.3:h:dlink:dir-823x:*:*:*:*:*:*:*, +1 more
- <= 250416
A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in versions through 250416. The issue arises in the '/goform/diag_ping' file, where the 'target_addr' parameter is not properly validated. This lack of validation allows attackers to inject malicious commands, which can be executed on the device. The vulnerability can be exploited remotely, and a public exploit is available.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
To reproduce this vulnerability, log into the router and navigate to the '/goform/diag_ping' endpoint. The 'target_addr' parameter can be manipulated by injecting commands, such as using a semicolon to separate commands. Once the payload is sent, the injected commands will be executed on the router's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.