CVE-2026-2175 Details
Description
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 250416 firmware version. The issue arises in the '/goform/set_upnp' endpoint, within the 'sub_420618' function. This vulnerability allows authenticated attackers to inject arbitrary operating system commands by manipulating the 'upnp_enable' parameter. The injection is possible because the application fails to properly sanitize newline characters, enabling attackers to terminate the intended command and execute malicious instructions with root privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/master-abc/cve/issues/31 | [email protected] | ExploitIssue Tracking |
| https://vuldb.com/?ctiid.344876 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.344876 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.749263 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.dlink.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-823x firmware | 250416 |
CPE
Remediation
| |
| dlink dir-823x | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 11, 2026 | Initial Analysis | [email protected] |
| Feb 8, 2026 | New CVE Received | [email protected] |