CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2026-04-24. EPSS: 87.9% chance of exploitation in the next 30 days.

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

Affected products

  • D-Link DIR-823X Firmware: version 240126 only; version 240802 only

Published 2025-03-25. Last modified 2026-06-17.