CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-29635

🔥 Known Exploited (CISA KEV)HIGH
7.2
CVSS Severity Score
EPSS Score32.2720%
EPSS Percentile88.45th
Published2025-03-25
Last Modified2026-06-17
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

Affected Platforms (CPE)

💻
Dlink

Dir 823x Firmware

= 240126= 240802

References & Advisories

関連する脆弱性情報