D-Link DIR-823X是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-823X 240126版本和240802版本存在安全漏洞,该漏洞源于授权攻击者通过向/goform/set_prohibiting发送POST请求,触发远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POST request to /goform/set_prohibiting, letting an authorized attacker execute arbitrary commands remotely, exploit requires attacker to be authorized. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2025/CVE-2025-29635.yaml | POC Details |
| 2 | D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POST request to /goform/set_prohibiting, letting an authorized attacker execute arbitrary commands remotely, exploit requires attacker to be authorized. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-29635.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-22230 | 7.8 HIGH | Authentication bypass vulnerability |
| CVE-2024-55030 | fprime 命令注入漏洞 | |
| CVE-2025-27837 | Artifex Ghostscript 路径遍历漏洞 | |
| CVE-2025-27831 | Artifex Ghostscript 安全漏洞 | |
| CVE-2025-27832 | Artifex Ghostscript 安全漏洞 | |
| CVE-2025-27830 | Artifex Ghostscript 安全漏洞 | |
| CVE-2025-27836 | Artifex Ghostscript 安全漏洞 | |
| CVE-2025-27835 | Artifex Ghostscript 安全漏洞 | |
| CVE-2025-27833 | Artifex Ghostscript 安全漏洞 | |
| CVE-2024-55029 | fprime 安全漏洞 | |
| CVE-2024-42533 | Convivance StandVoice SQL注入漏洞 | |
| CVE-2024-55028 | fprime 代码注入漏洞 | |
| CVE-2025-25373 | AquilaCMS 安全漏洞 | |
| CVE-2025-25371 | AquilaCMS 路径遍历漏洞 | |
| CVE-2025-25374 | AquilaCMS 资源管理错误漏洞 | |
| CVE-2025-25372 | AquilaCMS 缓冲区错误漏洞 | |
| CVE-2025-27834 | Artifex Ghostscript 安全漏洞 | |
| CVE-2024-48818 | IIT Bombay Bodhitree 安全漏洞 | |
| CVE-2025-30118 | Audi Universal Traffic Recorder App 信任管理问题漏洞 |
No comments yet