Metrics
Affected Vendors & Products
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dir-823x |
|
| Vendors & Products |
D-link
D-link dir-823x |
Mon, 08 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. | |
| Title | D-Link DIR-823X set_wan_settings sub_415028 command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-08T01:02:07.507Z
Updated: 2025-12-08T15:52:37.201Z
Reserved: 2025-12-07T08:07:20.088Z
Link: CVE-2025-14208
Updated: 2025-12-08T15:52:34.301Z
Status : Awaiting Analysis
Published: 2025-12-08T01:16:00.673
Modified: 2025-12-08T18:26:49.133
Link: CVE-2025-14208
No data.