Описание
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-29635
- https://github.com/mono7s/Dir-823x/blob/main/set_prohibiting/set_prohibiting.md
- https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-29635
Связанные уязвимости
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Уязвимость файла /goform/set_prohibiting микропрограммного обеспечения маршрутизаторов D-link DIR-823X AX3000, позволяющая нарушителю выполнить произвольные команды