D-Link DIR-823X OS Command Injection Vulnerability

Vulnerability

A critical command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 firmware version. The issue arises in the function 'sub_41E2A0' within the '/goform/set_mode' endpoint. The vulnerability allows remote attackers to inject operating system commands by manipulating the 'lan_gateway' parameter. This exploitation is possible because the router's firmware is no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device's operating system.

Reproduction

To reproduce this vulnerability, log into the router's web interface and navigate to the '/goform/set_mode' endpoint. Inject a command through the 'lan_gateway' parameter, which will be executed on the system. This can be automated with a script that handles the login process and token management.

Added: Jan 28, 2026, 10:25 PM
Updated: Jan 28, 2026, 10:25 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.8
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.