Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14821 | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. |
Mon, 11 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Command Execution via Command Injection in D-Link DIR-823X Firmware |
Sat, 09 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Command Execution via Command Injection in D-Link DIR-823X Firmware |
Tue, 05 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection Vulnerability in D-Link DIR-823X Allows Remote Execution |
Mon, 04 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection Vulnerability in D-Link DIR-823X Allows Remote Execution |
Sun, 03 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Command Execution via POST /goform/set_prohibiting in D‑Link DIR‑823X |
Fri, 01 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Command Execution via POST /goform/set_prohibiting in D‑Link DIR‑823X |
Fri, 24 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Fri, 24 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 03 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
Tue, 25 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-25T03:55:37.481Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29635
Updated: 2025-03-25T14:49:53.234Z
Status : Analyzed
Published: 2025-03-25T14:15:29.043
Modified: 2026-04-24T19:27:15.560
Link: CVE-2025-29635
No data.
OpenCVE Enrichment
Updated: 2026-05-11T18:15:41Z
EUVD