CVE-2023-0127: D-Link DWL-2600AP Firmware

High severity, CVSS 7.8. EPSS: 2% chance of exploitation in the next 30 days.

A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root.

Affected products

  • D-Link DWL-2600AP Firmware: version 4.2.0.17 only

Published 2023-02-11. Last modified 2026-06-17.