CVE-2026-1544: D-Link DIR-823X set_mode sub_41E2A0 os command injection
A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub41E2A0 of the file /goform/setmode. Performing a manipulation of the argument langateway results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1544?
The severity of CVE-2026-1544 is critical due to its potential for OS command injection affecting D-Link DIR-823X devices.
How do I fix CVE-2026-1544?
To fix CVE-2026-1544, update your D-Link DIR-823X firmware to the latest version provided by the manufacturer.
What types of attacks can CVE-2026-1544 facilitate?
CVE-2026-1544 can facilitate OS command injection attacks, allowing an attacker to execute arbitrary commands on the device.
Which devices are affected by CVE-2026-1544?
CVE-2026-1544 affects the D-Link DIR-823X router model with firmware version 250416.
How does CVE-2026-1544 operate?
CVE-2026-1544 operates by manipulating the 'lan_gateway' argument in the set_mode function, allowing unauthorized command execution.