D-Link DIR-823X set_prohibiting - Command Injection
CVE-2025-29635
Verified
Description
D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POST request to /goform/set_prohibiting, letting an authorized attacker execute arbitrary commands remotely, exploit requires attacker to be authorized.
Severity
High
CVSS Score
7.2
Exploit Probability
88%
Affected Product
dir-823x_firmware
Published Date
June 17, 2026
Template Author
pussycat0x
CVE-2025-29635.yaml
7.2Score
CVSS Metrics
CVE ID:
cve-2025-29635
CWE ID:
cwe-78
Remediation Steps
Update to the latest firmware version provided by D-Link or contact vendor for patches.