D-Link DIR-823X Command Injection Vulnerability in Wi-Fi Blacklist Management

Vulnerability

A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 firmware version. The issue arises in the '/goform/set_wifi_blacklists' function, where the 'macList' parameter is not properly validated. This lack of validation allows remote attackers to inject malicious commands that could be executed on the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected router.

Reproduction

To reproduce this vulnerability, log into the D-Link DIR-823X router and navigate to the Wi-Fi blacklist management feature. The 'macList' parameter can be manipulated by injecting malicious strings that exploit the command execution flaw. This can be done by sending a crafted request that includes the injected command in the 'macList' parameter.

Added: Sep 28, 2025, 6:18 AM
Updated: Sep 28, 2025, 6:18 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
5.8
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.