{"cve":"CVE-2026-1125","enrichment":{"created":"2026-01-19T09:18:53.420142+00:00","updated":"2026-06-18T11:30:04.053996+00:00","vendors":["d-link","d-link$PRODUCT$dir-823x"]},"epss":{"score":0.1574},"mitre":{"cpes":[],"created":"2026-01-18T16:02:08.755000+00:00","description":"A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV4_0":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}},"mitre_repo_path":"cves/2026/1xxx/CVE-2026-1125.json","references":["https://github.com/DavCloudz/cve/blob/main/D-link/DIR_823X/DIR-823X%20V250416%20Command%20Execution%20Vulnerability.md","https://vuldb.com/?ctiid.341717","https://vuldb.com/?id.341717","https://vuldb.com/?submit.734966","https://vuldb.com/?submit.743503","https://www.dlink.com/"],"title":"D-Link DIR-823X set_wifidog_settings sub_412E7C command injection","updated":"2026-02-23T08:39:23.157000+00:00","vendors":[],"weaknesses":["CWE-74","CWE-77"]},"nvd":{"cpes":["cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dir-823x_firmware:250126:*:*:*:*:*:*:*"],"created":"2026-01-18T16:15:50.810000+00:00","description":"A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{"score":5.5,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-1125.json","references":["https://github.com/DavCloudz/cve/blob/main/D-link/DIR_823X/DIR-823X%20V250416%20Command%20Execution%20Vulnerability.md","https://vuldb.com/?ctiid.341717","https://vuldb.com/?id.341717","https://vuldb.com/?submit.734966","https://vuldb.com/?submit.743503","https://www.dlink.com/"],"title":null,"updated":"2026-06-17T10:15:08.613000+00:00","vendors":["dlink","dlink$PRODUCT$dir-823x","dlink$PRODUCT$dir-823x_firmware"],"weaknesses":["CWE-74","CWE-77"]},"opencve":{"changes":[{"created":"2026-01-18T16:15:00+00:00","data":[{"details":{"new":"A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.","old":null},"type":"description"},{"details":{"new":"D-Link DIR-823X set_wifidog_settings sub_412E7C command injection","old":null},"type":"title"},{"details":{"added":["CWE-74","CWE-77"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/DavCloudz/cve/blob/main/D-link/DIR_823X/DIR-823X%20V250416%20Command%20Execution%20Vulnerability.md","https://vuldb.com/?ctiid.341717","https://vuldb.com/?id.341717","https://vuldb.com/?submit.734966","https://www.dlink.com/"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV3_1":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"cvssV4_0":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"fb2dba58-af7a-4088-b40a-5a398d4a32b1"},{"created":"2026-01-19T09:45:00+00:00","data":[{"details":["d-link","d-link$PRODUCT$dir-823x"],"type":"first_time"},{"details":{"added":["d-link","d-link$PRODUCT$dir-823x"],"removed":[]},"type":"vendors"}],"id":"c0e3ee31-0b1e-4839-98bc-8d70d7b1b607"},{"created":"2026-01-20T17:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"079c6a27-7e09-49d1-83c3-ecc3555165e0"},{"created":"2026-01-30T17:00:00+00:00","data":[{"details":["dlink","dlink$PRODUCT$dir-823x","dlink$PRODUCT$dir-823x_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dir-823x_firmware:250126:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["dlink","dlink$PRODUCT$dir-823x","dlink$PRODUCT$dir-823x_firmware"],"removed":[]},"type":"vendors"}],"id":"36ceefd6-1078-4518-a68f-b2bbbb684834"},{"created":"2026-02-23T08:45:00+00:00","data":[{"details":{"added":["https://vuldb.com/?submit.743503"],"removed":[]},"type":"references"}],"id":"6d2ba284-bedf-4b8e-bb83-f8304334d02f"}],"cpes":{"data":["cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dir-823x_firmware:250126:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2026-01-18T16:02:08.755000+00:00","provider":"mitre"},"description":{"data":"A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"},"provider":"mitre"},"cvssV3_0":{"data":{"score":7.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV3_1":{"data":{"score":7.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV4_0":{"data":{"score":6.9,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"},"provider":"mitre"},"epss":{"data":{"score":0.1574},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/DavCloudz/cve/blob/main/D-link/DIR_823X/DIR-823X%20V250416%20Command%20Execution%20Vulnerability.md","https://vuldb.com/?ctiid.341717","https://vuldb.com/?id.341717","https://vuldb.com/?submit.734966","https://vuldb.com/?submit.743503","https://www.dlink.com/"],"providers":["mitre","nvd"]},"title":{"data":"D-Link DIR-823X set_wifidog_settings sub_412E7C command injection","provider":"mitre"},"updated":{"data":"2026-04-18T05:30:25.847609+00:00","provider":"enrichment"},"vendors":{"data":["d-link","d-link$PRODUCT$dir-823x","dlink","dlink$PRODUCT$dir-823x","dlink$PRODUCT$dir-823x_firmware"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-74","CWE-77"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-01-18T16:02:08.755000+00:00","description":"A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"D-Link DIR-823X set_wifidog_settings sub_412E7C command injection","updated":"2026-01-20T16:41:40.353000+00:00","vendors":[],"vulnrichment_repo_path":"2026/1xxx/CVE-2026-1125.json","weaknesses":[]}}