CVE-2025-55848: Command Injection
Published Sep 26, 2025
·Updated
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the setcassword settings interface, as the httpcasswd parameter is not filtered by '&'to allow injection of reverse connection commands.
Affected Software
3 affected components
DIR DIR-823
All of the following
Dlink Dir-823x Firmware=250416
Dlink Dir-823x
Event History
Sep 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55848?
CVE-2025-55848 is classified as a Remote Code Execution (RCE) vulnerability.
2
How do I fix CVE-2025-55848?
To remediate CVE-2025-55848, update the DIR-823 firmware to the latest version provided by D-Link.
3
What systems are affected by CVE-2025-55848?
CVE-2025-55848 affects DIR-823 devices running firmware version 2025-04-16.
4
What is the nature of the vulnerability in CVE-2025-55848?
CVE-2025-55848 allows for command injection due to insufficient filtering of the http_casswd parameter.
5
Is there a public exploit for CVE-2025-55848?
Currently, there is no widely known public exploit for CVE-2025-55848, but the RCE risk should be taken seriously.