CVE-2020-25367: D-Link Dir-823g Firmware

Critical severity, CVSS 9.8. EPSS: 8.6% chance of exploitation in the next 30 days.

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

Affected products

  • D-Link Dir-823g Firmware: version 1.0.2b05 only

Published 2021-11-04. Last modified 2026-07-09.