CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/setprohibiting via the corresponding function, triggering remote command execution.
Other sources
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/setprohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29635?
CVE-2025-29635 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-29635?
To fix CVE-2025-29635, update the D-Link DIR-823X firmware to the latest version provided by D-Link.
Who is affected by CVE-2025-29635?
CVE-2025-29635 affects users of the D-Link DIR-823X routers with specific software versions.
What are the implications of exploiting CVE-2025-29635?
Exploiting CVE-2025-29635 allows an attacker to execute arbitrary commands on affected D-Link devices, which can lead to complete control of the device.
How can I determine if my D-Link DIR-823X is vulnerable to CVE-2025-29635?
You can determine if your device is vulnerable by checking the firmware version against the affected versions mentioned in the vulnerability report.