D-Link DIR-823X是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-823X 250416版本存在命令注入漏洞,该漏洞源于文件/goform/delete_prohibiting中函数uci_del对参数delvalue的错误操作,可能导致远程命令注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11100 | 6.3 MEDIUM | D-Link DIR-823X set_wifi_blacklists uci_set command injection |
| CVE-2025-11098 | 6.3 MEDIUM | D-Link DIR-823X set_wifi_blacklists command injection |
| CVE-2025-11097 | 6.3 MEDIUM | D-Link DIR-823X set_device_name command injection |
| CVE-2025-11096 | 6.3 MEDIUM | D-Link DIR-823X diag_traceroute command injection |
| CVE-2025-11095 | 6.3 MEDIUM | D-Link DIR-823X delete_offline_device command injection |
| CVE-2025-11092 | 6.3 MEDIUM | D-Link DIR-823X set_switch_settings sub_412E7C command injection |
No comments yet