Dir 823x
Vendor:
First CVE: Jul 19, 2024 · Active for 2 years
38
Total CVEs
More Total CVEs than 97% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 823x over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2024
2 years ago
Most Recent CVE
Feb 9, 2026
166 days ago
CVE Severity & Scoring
Dir 823x38 CVEs
74%
18%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (97.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.6%)
Attack Complexity
Low37 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None38 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low14 (36.8%)
High14 (36.8%)
None10 (26.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-29635HIGH A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /g | Mar 25, 2025 | 7.2 | 96 | YES | YES |
CVE-2026-1125CRITICAL A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of th | Jan 18, 2026 | 9.8 | 37 | NO | NO |
CVE-2025-10123CRITICAL A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulat | Sep 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11100HIGH A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. I | Sep 28, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-10814HIGH A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation | Sep 22, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-10634HIGH A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment V | Sep 18, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-10401HIGH A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument tar | Sep 14, 2025 | 8.8 | 31 | NO | NO |
CVE-2025-11099HIGH A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument del | Sep 28, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-11098HIGH A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList r | Sep 28, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-11096HIGH A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr | Sep 28, 2025 | 8.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Dir 823x
Top CWEs
Versions
No cataloged versions.