CVE-2025-29635: D-Link DIR-823X
EPSS87.9%No. 504 of 1739 in KEV
CVE year2025~1 yrs before listing
Same vendor in KEV26
Same product1
| Field | Value |
|---|---|
| Vendor | D-Link |
| Product | DIR-823X |
| Name | D-Link DIR-823X Command Injection Vulnerability |
| Added to KEV | 2026-04-24 |
| US federal due date | 2026-05-08 |
| Ransomware use | Unknown |
| CWE | CWE-77 |
CISA description
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A D-Link DIR-823X vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-24.