Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31367 | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection commands. |
Mon, 09 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:dlink:dir-823x_firmware:250416:*:*:*:*:*:*:* |
Fri, 03 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink dir-823x
Dlink dir-823x Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:2025-04-16:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink dir-823x
Dlink dir-823x Firmware |
Mon, 29 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-823 |
|
| Vendors & Products |
Dlink
Dlink dir-823 |
Fri, 26 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Fri, 26 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection commands. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-29T15:27:54.542Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-55848
Updated: 2025-09-26T20:35:50.139Z
Status : Analyzed
Published: 2025-09-26T17:15:36.353
Modified: 2026-03-09T15:18:06.967
Link: CVE-2025-55848
No data.
OpenCVE Enrichment
Updated: 2025-09-29T09:31:12Z
EUVD