Historical catalog analysis: CISA added this entry on April 24, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2025-29635 is a command injection vulnerability (CWE-77) identified in the D-Link DIR-823X. The flaw allows an attacker with authorized access to execute arbitrary commands on the remote device. This is achieved by sending a specifically crafted POST request to the /goform/set_prohibiting endpoint.
Exposure and applicability
This vulnerability applies to organizations utilizing D-Link DIR-823X hardware. Because exploitation requires authorization, the primary exposure path involves attackers who have already obtained valid credentials or insiders with administrative access to the device’s web interface.
Infrastructure owners should note that this product may be classified as end-of-life (EoL) or end-of-service (EoS), meaning official vendor support and security updates may no longer be available for the affected hardware.
Remediation priorities
Based on the reported EoL/EoS status of the device, our analysis suggests the following priority actions:
- Hardware Decommissioning: The primary recommendation is to discontinue the use of the DIR-823X. Replacing legacy, unsupported hardware with current, supported equipment is the most effective way to eliminate this specific exposure.
- Inventory Audit: Identify all instances of the DIR-823X across the network environment to ensure no rogue or forgotten units remain active.
- Access Restriction: If immediate replacement is not possible, restrict access to the device’s management interface to a highly limited set of trusted IP addresses to reduce the likelihood of an authorized attacker reaching the vulnerable endpoint.
How to validate remediation
Verification must move beyond simple version checks, as EoL status implies that a patch may not exist. Remediation is verified when:
* Asset Removal: The device is physically removed from the network and confirmed absent via updated asset inventories and active network scans.
* Connectivity Termination: Network logs confirm that no traffic is being routed to or from the affected hardware.
Limits and open questions
There is currently no information regarding whether this vulnerability is being leveraged in known ransomware campaigns. Furthermore, because the product is potentially EoL/EoS, there is a significant risk that other undiscovered vulnerabilities exist within the same firmware. Replacing the device reduces the risk associated with CVE-2025-29635 but does not guarantee the absence of other architectural flaws inherent in legacy hardware.
Source and editorial note
CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability · Source date: April 24, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: April 27, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 13, 2026 at 00:32 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗