Summary
The vulnerability affects the D-Link DIR-823X router’s web management interface, specifically the /goform/set_prohibiting CGI handler. A crafted POST request can inject shell metacharacters into a field that is later passed into a system() call, leading to arbitrary command execution on the device. Public proof-of-concept code exists, and Akamai reported active exploitation in the wild that installs Mirai-style malware.
Why Planned Fix?
5/6Exploitation Details
Execute arbitrary commands on the router as administrator/root
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| DIR-823X AX3000 Dual-Band Gigabit Wireless Router | firmware 240126 and 240802 |
A consumer/SMB wireless router that provides wired and wireless network access plus web-based administration.
Affected ComponentWeb management CGI handler for the set_prohibiting function, where user-supplied form data is passed into a system command.
Web management CGI handler for the set_prohibiting function, where user-supplied form data is passed into a system command.
Affected Endpoints(3)/goform/set_prohibiting, /goform/login…
Retire and replace DIR-823X devices; if temporary use is unavoidable, restrict access to the web admin interface to trusted networks and limit exposure of the router management plane.
Retire and replace DIR-823X devices; if temporary use is unavoidable, restrict access to the web admin interface to trusted networks and limit exposure of the router management plane.
Not available
Not available
Probability of exploitation in the next 30 days
Worse than 79% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (2)
- •cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:*
- •cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | CVE-2025-29635 Detail |
| www.akamai.com | CVE-2025-29635: Mirai Campaign Targets D-Link Devices |
| supportannouncement.us.dlink.com | DIR-823X End-of-Life Notice |
| gist.github.com | DIR-823X Remote Command Execution PoC |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
Priority History
Initial analysis
Reassessed to Planned Fix
Elevated — all critical conditions met
Reassessed to Planned Fix