D-Link DIR-823X OS Command Injection Vulnerability

Vulnerability

A remote command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 version. The issue arises in the backend function sub_4211C8 within the /goform/set_filtering endpoint. This vulnerability allows authenticated attackers to execute arbitrary shell commands with root privileges by manipulating user-supplied parameters. The exploitation bypasses a basic blacklist filter, enabling the injection of commands through the newline character.

Impact

Exploitation of this vulnerability allows for unauthorized command execution on the router's operating system with root privileges.

Reproduction

To reproduce this vulnerability, an authenticated user can send a request to the /goform/set_filtering endpoint with crafted input that includes the newline character. This input will bypass the filter and inject commands into the execution context.

Added: Feb 9, 2026, 3:20 AM
Updated: Feb 9, 2026, 3:20 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
5.6
remediation
0.0
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.