← Back to browse · API

CVE-2025-29635

Severity
HIGH
CVSS
7.2
EPSS
0.89641
Risk score
56.37
CISA KEV
Yes
PoC
No
Published
2025-03-25
Modified
2026-04-25
First seen
2026-08-07
Aliases
EUVD-2025-14821, GHSA-M9WC-3H85-PP63
Products
D-Link:DIR-823X, n/a:n/a n/a
Sources
cisa.gov CVE-2025-29635
euvd EUVD-2025-14821

Description

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

References