CVE-2026-2143: D-Link DIR-823X DDNS Service set_ddns os command injection
A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/setddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2143?
CVE-2026-2143 is considered a medium-severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-2143?
To fix CVE-2026-2143, update your D-Link DIR-823X firmware to the latest version provided by D-Link.
What components are affected by CVE-2026-2143?
CVE-2026-2143 affects the DDNS Service component of the D-Link DIR-823X router.
What could an attacker achieve with CVE-2026-2143?
An attacker could exploit CVE-2026-2143 to execute arbitrary OS commands on the affected device.
Is there a workaround for CVE-2026-2143?
Currently, the recommended action is to apply the firmware update, as there are no effective workarounds for CVE-2026-2143.