CVE-2026-2081Disclosure(dlink / dir-823x)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dlink dir-823x systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-823x
  • dir-823x_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
dir-823xdir-823x_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-07: 1Mentions · 2026-02-11: 1Patch / Workaround · 2026-02-11: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-11: 102-0702-11
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-071
Disclosure1
2026-02-111
Patch1
Full discourse2 posts
  • DT en Español@DigitalTrendsEs
    Patch

    Microsoft ha resuelto una vulnerabilidad grave que afectaba el #BlocdeNotas de #Windows11, permitiendo a actores maliciosos ejecutar código de forma remota en máquinas comprometidas. La falla de seguridad, catalogada como CVE-2026-2081, ha sido parcheada… https://es.digitaltrends.com/computadoras/microsoft-cierra-vulnerabilidad-critica-en-el-bloc-de-notas-de-windows-11/?utm_source=twitter&utm_medium=socialorg&utm_campaign=rss-feed

    Post summary

    Microsoft ha cerrado con un parche la vulnerabilidad CVE-2026-2081, que permitía la ejecución remota de código en el Bloc de notas de Windows 11.

    01011326
    183.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2081 A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argumen… https://www.cve.org/CVERecord?id=CVE-2026-2081

    Post summary

    A vulnerability (CVE-2026-2081) was identified in the D-Link DIR-823X firmware, affecting an unknown function in the /goform/set_password endpoint, likely due to argument manipulation.

    00000265
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-823x---
OSdlinkdir-823x_firmware250416--

Explore more