D-Link DIR-823X command injection in WAN settings handler

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-14208?

CVE-2025-14208 is a vulnerability classified as Improper Neutralization of Special Elements used in a Command ('Command Injection') and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), affecting DIR-823X (affected versions: 20250416). This vulnerability is rated Medium, with a CVSS score of 5.3. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

Affected products and scope

  • The CNA describes D-Link DIR-823X as affected through version 20250416.
  • Structured affected data explicitly marks version 20250416 as affected. No other product branch or parallel release branch is confirmed in the record.
  • No fixed release, patch, or unaffected version boundary is provided. The status of releases after 20250416 remains unverified.

Technical details

D-Link DIR-823X has a command injection flaw in the sub_415028 function reached through the /goform/set_wan_settings endpoint. The ppp_username argument is not properly validated, allowing attacker-controlled data to enter a command execution path. Available evidence indicates that low-level access is required and that the request can be sent over the network without user interaction. The exact shell invocation, execution sink, and privileges of the affected process remain unknown.

Exploitability

The flaw is remotely reachable through the router's network administration interface. The supplied attack characteristics indicate low privileges are required, attack complexity is low, and no additional user interaction is needed. Public GitHub material contains a PoC for the flaw, but this entry does not reproduce the payload or exploit sequence. A GCVE catalog entry returned during research currently marks exploitation as confirmed; that status is catalog intelligence and is not a separate confirmation from D-Link or CISA. The reviewed evidence does not identify a specific campaign, victim, or malware family.

Technical impact

The confirmed technical outcome is that data supplied through ppp_username can lead to command injection on the router itself. If the command executes with the administration service's privileges, an attacker may be able to read or modify data available to that service, change device configuration, or disrupt operation. The record does not establish the resulting privilege level, access to the underlying operating system, or compromise of other systems. Risk to the wider organization is therefore possible but must be assessed against the configuration and runtime privileges of each device.

Business impact

Successful exploitation could allow an attacker to change router configuration or disrupt network services, depending on the privileges of the handling process. Changes to WAN or related settings could cause loss of connectivity, traffic redirection, or reduced trust in the local network. The flaw could also support persistence on the device or use of the router as a staging point for later activity, but those outcomes are not confirmed for every deployment. Actual exposure depends on where the administration interface is reachable and the runtime privileges provided by the firmware.

Remediation

  1. Check D-Link support notices and upgrade only to firmware that D-Link explicitly confirms as fixing this flaw. No exact fixed release is confirmed by the available evidence.
  2. Until a verified fix is available, restrict the administration interface to trusted management networks and remove unnecessary access from untrusted networks.
  3. Review devices within the affected scope, prioritizing systems with broadly reachable administration interfaces or unexpected WAN configuration changes.
  4. If exploitation is suspected, isolate the router, preserve logs and configuration, change administrative credentials from a trusted device, and restore firmware and configuration through the organization's trusted recovery process.
  5. Do not treat the absence of suspicious logs as proof of safety because the record does not provide complete indicators of compromise or require a particular logging mechanism.

Detection

  1. Inventory D-Link DIR-823X devices and verify the firmware identifier currently installed. Compare the result with the affected scope in this entry, and do not assume that an unverified branch is safe.
  2. Determine whether the administration interface exposes /goform/set_wan_settings and whether that interface is reachable from untrusted networks.
  3. If the router retains administrative or HTTP logs, review requests to this endpoint and unexpected WAN configuration changes. Treat these as review signals, not confirmed indicators of compromise.
  4. Check WAN and DNS settings, administrator accounts, and firmware changes for unauthorized modifications. The absence of suspicious logs or changes does not prove that the device was not exploited.
  5. If compromise is suspected, isolate the device and preserve logs and configuration data before recovery.
Sources (20)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan