CVE-2025-29635 Scanner

CVE-2025-29635 Scanner - Command Injection vulnerability in D-Link DIR-823X

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

3 weeks 14 hours

Scan only one

Domain, Subdomain, IPv4

Toolbox

The D-Link DIR-823X is a popular wireless router used in both home and small office environments. It is designed to provide high-speed wireless connectivity and advanced network settings for its users. Offered by D-Link, a leading global provider of networking solutions, the DIR-823X router supports multiple connected devices. With features such as parental controls, traffic analysis, and enhanced security options, it is often chosen for everyday internet browsing and media streaming. Its ease of setup and broad range makes it a preferred option for non-technical users as well.

The Command Injection vulnerability in the D-Link DIR-823X allows authorized attackers to execute arbitrary commands remotely. This type of vulnerability can lead to severe security implications as it provides undesired control over the device's operations. Specifically, a POST request directed at the /goform/set_prohibiting endpoint is manipulated to enable exploits. If an attacker has the necessary authentication, they can potentially manipulate the system commands offered by the router's firmware. This precarious access possibility raises an increased risk of the device being compromised.

This vulnerability is associated with the endpoint /goform/set_prohibiting, where a POST request can be sent with malicious payloads. The parameter 'macaddr' within this request is vulnerable and exploited in this context. By using a crafted payload that incorporates command line instructions, an attacker bypasses security controls. The attack includes interfacing with external command repositories through DNS requests, often using tools like interactsh for exploiting purposes. Successful exploitation might result in a HTTP 200 status code, indicating command execution on the device.

When exploited, this vulnerability potentially allows an attacker to perform arbitrary command execution and gain unauthorized control of the router. This could lead to system misconfigurations, data interception, network outages, or using the compromised router as a launchpad for further attacks on connected devices. This can substantially impact the confidentiality, integrity, and availability of network communications extending beyond the affected devices themselves.

REFERENCES

Get started to protecting your digital assets