EUVD-2025-14821
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 24 Apr 2026. Evidence sources: cisa_kev.
- ENISA score
- 7.2 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
