CVE-2025-29635 Scanner
CVE-2025-29635 Scanner - Command Injection vulnerability in D-Link DIR-823X
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
3 weeks 14 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
The D-Link DIR-823X is a popular wireless router used in both home and small office environments. It is designed to provide high-speed wireless connectivity and advanced network settings for its users. Offered by D-Link, a leading global provider of networking solutions, the DIR-823X router supports multiple connected devices. With features such as parental controls, traffic analysis, and enhanced security options, it is often chosen for everyday internet browsing and media streaming. Its ease of setup and broad range makes it a preferred option for non-technical users as well.
The Command Injection vulnerability in the D-Link DIR-823X allows authorized attackers to execute arbitrary commands remotely. This type of vulnerability can lead to severe security implications as it provides undesired control over the device's operations. Specifically, a POST request directed at the /goform/set_prohibiting endpoint is manipulated to enable exploits. If an attacker has the necessary authentication, they can potentially manipulate the system commands offered by the router's firmware. This precarious access possibility raises an increased risk of the device being compromised.
This vulnerability is associated with the endpoint /goform/set_prohibiting, where a POST request can be sent with malicious payloads. The parameter 'macaddr' within this request is vulnerable and exploited in this context. By using a crafted payload that incorporates command line instructions, an attacker bypasses security controls. The attack includes interfacing with external command repositories through DNS requests, often using tools like interactsh for exploiting purposes. Successful exploitation might result in a HTTP 200 status code, indicating command execution on the device.
When exploited, this vulnerability potentially allows an attacker to perform arbitrary command execution and gain unauthorized control of the router. This could lead to system misconfigurations, data interception, network outages, or using the compromised router as a launchpad for further attacks on connected devices. This can substantially impact the confidentiality, integrity, and availability of network communications extending beyond the affected devices themselves.
REFERENCES