CVE-2026-2143Disclosure(dlink / dir-823x)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dlink dir-823x systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-823x
  • dir-823x_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dir-823xdir-823x_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-08: 3Mentions · 2026-02-13: 1Mentions · 2026-03-09: 1Patch / Workaround · 2026-02-08: 2Technical Details · 2026-02-08: 2Technical Details · 2026-02-13: 1Technical Details · 2026-03-09: 102-0802-1303-09
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-083
Disclosure1General1Patch1
2026-02-131
General1
2026-03-091
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-2143 A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Serv… https://www.cve.org/CVERecord?id=CVE-2026-2143

    Post summary

    The statement briefly references a CVE affecting a D-Link router’s DDNS component but offers no technical, exploit, or remediation details.

    10010269
    56.5K followersView on X
  • David@DavidMarquet19
    Disclosure

    📌 Top CVEs recientes (CVSS>=7.0): 1. 🛠️ CVE-2026-2155 (CVSS: 7.2) 2. 🛠️ CVE-2026-2152 (CVSS: 7.2) 3. 🛠️ CVE-2026-2151 (CVSS: 7.2) 4. 🛠️ CVE-2026-2143 (CVSS: 7.2) 5. 🛠️ CVE-2026-2142 (CVSS: 7.2) #CyberSecurity #CVE #Infosec

    Post summary

    The tweet announces five recent CVEs, all rated CVSS 7.2, but provides no details on exploitation, patches, or PoC.

    0000042
    167 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-2143 (CVSS:7.3, HIGH) is Analyzed. A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the ..https://nvd.nist.gov/vuln/detail/CVE-2026-2143 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post merely announces CVE‑2026‑2143 for a D‑Link router, provides a CVSS score and an NVD link, but offers no evidence of exploitation, patches, or detailed technical data.

    0000037
    171 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity: OS command injection found in D-Link DIR-823X (v250416). Remote exploit risk — no patch yet. Restrict remote access & monitor for suspicious activity! Details: https://radar.offseq.com/threat/cve-2026-2143-os-command-injection-in-d-link-dir-8-43a9e1df #OffSeq ... https://t.co/pqs4uYie60

    Post summary

    High‑severity OS command injection discovered in D‑Link DIR‑823X (v250416); no patch available yet—advised to restrict remote access and monitor for suspicious activity.

    0000035
    268 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    ⚠️ HIGH severity: OS command injection found in D-Link DIR-823X (fw 250416). Attackers with privileges can execute remote commands — no user interaction needed! Restrict remote access & monitor traffic. Patch ASAP! https://radar.offseq.com/threat/cve-2026-2143-os-command-injec... https://t.co/rLcaxqMSlP

    Post summary

    CVE-2026-2143 is a high‑severity OS command injection in D-Link DIR‑823X firmware that permits remote command execution with privileges. Users are urged to restrict remote access, monitor traffic, and apply a patch immediately.

    0000058
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-823x---
OSdlinkdir-823x_firmware250416--

Explore more