CVE-2026-2063: D-Link DIR-823X Web Management set_ac_server os command injection
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/setacserver of the component Web Management Interface. The manipulation of the argument acserver results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2063?
CVE-2026-2063 is considered a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2026-2063?
To fix CVE-2026-2063, users should update the D-Link DIR-823X firmware to the latest version provided by D-Link.
What component is affected by CVE-2026-2063?
CVE-2026-2063 affects the Web Management Interface specifically the /goform/set_ac_server file in the D-Link DIR-823X router.
What type of vulnerability is CVE-2026-2063?
CVE-2026-2063 is classified as an OS command injection vulnerability.
Who is affected by CVE-2026-2063?
Users of the D-Link DIR-823X router are affected by CVE-2026-2063.