Exploited Vulnerabilities Daily
🌐 English

Home › D-Link

CVE-2025-29635: D-Link DIR-823X

EPSS87.9%No. 504 of 1739 in KEV
CVE year2025~1 yrs before listing
Same vendor in KEV26
Same product1
FieldValue
VendorD-Link
ProductDIR-823X
NameD-Link DIR-823X Command Injection Vulnerability
Added to KEV2026-04-24
US federal due date2026-05-08
Ransomware useUnknown
CWECWE-77

CISA description

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD — CVE-2025-29635

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A D-Link DIR-823X vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-24.