D-Link DIR-823X OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 firmware version. The issue arises in the function sub_4175CC within the file /goform/set_static_route_table. This vulnerability allows authenticated attackers to inject arbitrary operating system commands by manipulating the newline character in several parameters, including interface, destip, netmask, gateway, and metric. The injected commands are executed with root privileges, posing a significant security risk.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the router's operating system, with the injected commands executed as the root user.

Reproduction

To reproduce this vulnerability, an authenticated user can send a POST request to the /goform/set_static_route_table endpoint with a payload that includes a newline character in the gateway parameter. This newline injection bypasses input validation and command sanitization, allowing the attacker to execute arbitrary commands on the device.

Added: Feb 8, 2026, 3:18 PM
Updated: Feb 8, 2026, 3:18 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
6.2
remediation
0.0
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.