A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Metrics
Affected Vendors & Products
References
History
Sun, 08 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. | |
| Title | D-Link DIR-823X Configuration set_dmz sub_4208A0 os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-08T14:02:08.815Z
Reserved: 2026-02-07T08:26:16.969Z
Link: CVE-2026-2155
No data.
Status : Received
Published: 2026-02-08T14:16:26.027
Modified: 2026-02-08T14:16:26.027
Link: CVE-2026-2155
No data.
OpenCVE Enrichment
No data.