CVE-2024-51023: D-Link Dir-823g Firmware

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

Affected products

  • D-Link Dir-823g Firmware: version 1.0.2b05 only

Published 2024-11-05. Last modified 2026-06-17.