Description
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
In plain language
AI Act nowThis is a router bug on D-Link DIR-823X devices (firmware 240126 and 240802) that lets a logged-in attacker run commands on the router from the internet; if you only use the router normally, your main risk is an attacker already getting authorized access, so you should act now if your router is in that firmware range.
CVE-2025-29635 is a command injection (CWE-77) in D-Link DIR-823X AX3000 / firmware, reachable remotely via a POST request to /goform/set_prohibiting, where an authorized attacker can inject input to trigger arbitrary command execution on the device.
What to do now
- Check whether your D-Link DIR-823X AX3000 router is running firmware versions 240126 or 240802.
- If you are on 240126 or 240802, immediately follow D-Link’s mitigation guidance for CVE-2025-29635 (or the specific steps they provide for /goform/set_prohibiting).
- If D-Link does not provide working mitigations for your exact device/firmware, discontinue use of the device as CISA recommends and replace it.
- Reduce the chance of an attacker gaining “authorized” access: review router admin access (especially any remote/admin-from-internet access) and restrict it to trusted internal use only.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-29635 and every CVE in our database. Create a free account — no credit card required.
Create Free Account