CVE-2026-2120: D-Link DIR-823X Configuration Parameter set_server_settings os command injection
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/setserversettings of the component Configuration Parameter Handler. The manipulation of the argument terminaladdr/serverip/serverport leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2120?
CVE-2026-2120 is classified as a high-severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2026-2120?
To fix CVE-2026-2120, users should update the D-Link DIR-823X firmware to the latest version released by D-Link.
What are the potential impacts of CVE-2026-2120?
If exploited, CVE-2026-2120 could allow an attacker to execute arbitrary commands on the affected system.
Which products are affected by CVE-2026-2120?
CVE-2026-2120 specifically affects the D-Link DIR-823X router.
How can I determine if my device is vulnerable to CVE-2026-2120?
Users can check the firmware version of their D-Link DIR-823X and compare it against the latest available version from D-Link to determine vulnerability.