CVE-2025-2717: D-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injection
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub41710C of the file /goform/diagnslookup of the component HTTP POST Request Handler. The manipulation of the argument targetaddr leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2717?
CVE-2025-2717 is classified as a critical vulnerability.
How does CVE-2025-2717 affect D-Link DIR-823X routers?
CVE-2025-2717 affects the HTTP POST Request Handler in the D-Link DIR-823X, allowing manipulation of the argument target_addr.
What are the affected versions for CVE-2025-2717?
CVE-2025-2717 affects D-Link DIR-823X routers running firmware versions between 240126 and 240802.
What type of exploitation is possible with CVE-2025-2717?
CVE-2025-2717 may lead to OS command injection via the affected HTTP POST request processing.
How can organizations protect against CVE-2025-2717?
Organizations should update their D-Link DIR-823X firmware to the latest version that patches CVE-2025-2717.