CVE-2026-2061: D-Link DIR-823X set_ipv6 sub_424D20 os command injection
Published Feb 6, 2026
·Updated
A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub424D20 of the file /goform/setipv6. Executing a manipulation can lead to os command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
3 affected components
D-Link DIR-823X
All of the following
Dlink Dir-823x Firmware=250416
Dlink Dir-832x
Event History
Feb 6, 2026
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2061?
The severity of CVE-2026-2061 is considered high due to its potential for remote command injection.
2
How do I fix CVE-2026-2061?
To fix CVE-2026-2061, update your D-Link DIR-823X router to the latest firmware version provided by D-Link.
3
Can CVE-2026-2061 be exploited remotely?
Yes, CVE-2026-2061 can be exploited remotely, allowing attackers to execute commands on the affected device.
4
What devices are affected by CVE-2026-2061?
CVE-2026-2061 affects the D-Link DIR-823X router specifically.
5
What kind of vulnerability is CVE-2026-2061?
CVE-2026-2061 is categorized as an OS command injection vulnerability.