CVE-2026-2129

Severity CVSS v4.0:
HIGH
Type:
CWE-77 Command Injection
Publication date:
08/02/2026
Last modified:
08/02/2026

Description

A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performing a manipulation of the argument ac_ipaddr/ac_ipstatus/ap_randtime results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.