CVE-2026-2157Disclosure(dlink / dir-823x)

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch dlink dir-823x systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument interface/destip/netmask/gateway/metric leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-823x
  • dir-823x_firmware

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
dir-823xdir-823x_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-08: 2Patch / Workaround · 2026-02-08: 1Technical Details · 2026-02-08: 202-08
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2157 A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation… https://www.cve.org/CVERecord?id=CVE-2026-2157

    Post summary

    The post announces the discovery of CVE‑2026‑2157 in D‑Link DIR‑823X routers, noting the specific function affected, but does not provide proof‑of‑concept, exploitation tools, or patch information.

    00010204
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: OS command injection in D-Link DIR-823X (fw 250416) lets remote attackers run commands with no auth required! Patch ASAP or segment networks. Details: https://radar.offseq.com/threat/cve-2026-2157-os-command-injection-in-d-link-dir-8-f7732c6f #OffSeq #DL... https://t.co/94A0lgyffc

    Post summary

    A high‑severity OS command injection in D-Link DIR‑823X allows unauthenticated remote execution; immediate patching or network segmentation is advised.

    00000144
    268 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-823x---
OSdlinkdir-823x_firmware250416--

Explore more