CVE List

CVE-2026-2143

Critical 7.2

A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Published February 8, 2026.

Affected software

Get alerts for Dlink Dir-823x Firmware

Reference links