{"id":"CVE-2025-29635","vendor_project":"D-Link","product":"DIR-823X","vulnerability_name":"D-Link DIR-823X Command Injection Vulnerability","date_added":"2026-04-24","due_date":"2026-05-08","known_ransomware_use":"Unknown","short_description":"D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cwes":"CWE-77","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2025-03-25","nvd_status":"Analyzed","epss":0.87944,"epss_percentile":0.99758,"cvss_score":7.2,"days_published_to_kev":395,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2025-29635","by":"CyberMax"}