D-Link DIR-823G UPnP Service Improper Authorization Vulnerability

Vulnerability

A critical vulnerability exists in the D-Link DIR-823G router, specifically in version 1.0.2B05_20181207. The issue arises in the UPnP service's SetUpnpSettings function within the /HNAP1/ file. This vulnerability allows for improper authorization through manipulation of the SOAPAction argument, enabling remote exploitation. Notably, this vulnerability affects products that are no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability could lead to unauthorized access or actions being performed on the device, potentially allowing for further attacks or manipulation of the device's functions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.