Vulnerability Details CVE-2026-2143
A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 8.3
Products affected by CVE-2026-2143
-
cpe:2.3:h:dlink:dir-823x:-
-
cpe:2.3:o:dlink:dir-823x_firmware:250416