CVE-2025-29635
HIGHA command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
Published: 3/25/2025Modified: 4/24/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (3)
https://github.com/mono7s/Dir-823x/blob/main/set_prohibiting/set_prohibiting.mdExploitThird Party Advisoryhttps://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devicesExploitThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-29635US Government Resource