A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
References
Configurations
No configuration.
History
08 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-08 01:16
Updated : 2025-12-08 18:26
NVD link : CVE-2025-14208
Mitre link : CVE-2025-14208
CVE.ORG link : CVE-2025-14208
JSON object : View
Products Affected
No product.
