CVE-2025-2359: D-Link DIR-823G DDNS Service HNAP1 SetDDNSSettings improper authorization
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B0520181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2359?
CVE-2025-2359 is classified as a critical vulnerability.
How do I fix CVE-2025-2359?
To fix CVE-2025-2359, update the D-Link DIR-823G firmware to the latest version provided by D-Link.
What is the impact of CVE-2025-2359?
CVE-2025-2359 allows improper authorization through the SetDDNSSettings function, potentially leading to unauthorized access.
Which devices are affected by CVE-2025-2359?
CVE-2025-2359 specifically affects the D-Link DIR-823G model.
What component does CVE-2025-2359 involve?
CVE-2025-2359 involves the DDNS Service component of the D-Link DIR-823G.