CVE-2026-1125: D-Link DIR-823X Firmware

Critical severity, CVSS 9.8. EPSS: 15.7% chance of exploitation in the next 30 days.

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

  • D-Link DIR-823X Firmware: version 250126 only

Published 2026-01-18. Last modified 2026-06-17.