Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-11095

CVE-2025-11095: D-Link DIR-823X Firmware RCE Vulnerability

CVE-2025-11095 is a remote code execution vulnerability in D-Link DIR-823X firmware affecting the delete_offline_device function. Attackers can exploit command injection to execute arbitrary code. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-11095 Overview

CVE-2025-11095 is a command injection vulnerability affecting the D-Link DIR-823X router running firmware version 250416. The flaw resides in the /goform/delete_offline_device endpoint, where the delvalue parameter is passed to a shell context without proper sanitization. Authenticated attackers can manipulate this argument to execute arbitrary operating system commands on the device over the network. Public disclosure of exploitation details has occurred through VulDB advisory #326176 and a GitHub write-up, increasing the likelihood of opportunistic use against exposed devices. The vulnerability maps to CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component).

Critical Impact

Authenticated remote attackers can inject operating system commands through the delvalue parameter, leading to arbitrary command execution on affected D-Link DIR-823X routers.

Affected Products

  • D-Link DIR-823X router hardware
  • D-Link DIR-823X firmware build 250416
  • Deployments exposing the web management interface to untrusted networks

Discovery Timeline

  • 2025-09-28 - CVE-2025-11095 published to the National Vulnerability Database
  • 2026-04-29 - Last updated in NVD database

Technical Details for CVE-2025-11095

Vulnerability Analysis

The vulnerability exists in the request handler for /goform/delete_offline_device, a web interface endpoint intended to remove cached entries for offline clients. The handler accepts a user-supplied delvalue argument and uses it when constructing a system command without performing input validation or escaping shell metacharacters. Attackers who can reach the management interface and supply a crafted parameter can break out of the intended command context and append arbitrary shell instructions. According to the public VulDB advisory, the exploit is publicly available, which lowers the barrier for reuse against unpatched devices.

Root Cause

The root cause is improper neutralization of special elements passed to a downstream OS command interpreter ([CWE-74]). The firmware concatenates the delvalue parameter directly into a shell invocation rather than passing it through a safe argument array or applying an allowlist. Characters such as ;, |, &, and backticks are interpreted by the shell, allowing command chaining.

Attack Vector

Exploitation requires network reachability to the router's HTTP management interface and a valid low-privileged session. The attacker submits a POST request to /goform/delete_offline_device with a delvalue payload that contains shell metacharacters followed by attacker-chosen commands. Successful exploitation results in command execution in the context of the web server process on the embedded device, which on consumer routers typically runs with elevated privileges. Refer to the GitHub documentation on device deletion and VulDB CTI Advisory #326176 for technical details. No verified proof-of-concept code is reproduced here.

Detection Methods for CVE-2025-11095

Indicators of Compromise

  • HTTP POST requests to /goform/delete_offline_device containing shell metacharacters such as ;, |, &, $(), or backticks in the delvalue parameter.
  • Unexpected outbound connections originating from the router to attacker infrastructure following management-interface activity.
  • New or modified files in writable firmware locations such as /tmp or /var that were not introduced by an administrator.

Detection Strategies

  • Inspect web server and router access logs for malformed delvalue values targeting the /goform/delete_offline_device endpoint.
  • Deploy network IDS signatures that flag command-injection patterns in HTTP request bodies destined for D-Link DIR-823X management ports.
  • Correlate authentication events on the router with subsequent administrative endpoint requests to identify credential reuse abuse.

Monitoring Recommendations

  • Forward router syslog and web access logs to a centralized analytics platform for retention and search.
  • Alert on any internet-exposed management interface for the DIR-823X identified through external attack-surface scans.
  • Track firmware version inventory so that devices running build 250416 are prioritized for remediation.

How to Mitigate CVE-2025-11095

Immediate Actions Required

  • Restrict access to the router web management interface to trusted internal networks and disable WAN-side administration.
  • Rotate administrative credentials and remove unused low-privileged accounts that could be abused to reach the vulnerable endpoint.
  • Monitor D-Link's support portal for a firmware update addressing CVE-2025-11095 and apply it once available.

Patch Information

At the time of publication, no vendor advisory or fixed firmware build has been linked to this CVE in the NVD record. Administrators should consult the D-Link Security Overview for firmware releases that supersede build 250416 and reference VulDB #326176 for advisory updates.

Workarounds

  • Place the DIR-823X behind a network segment that blocks untrusted HTTP/HTTPS access to its management interface.
  • Enforce strong, unique credentials and disable any guest or low-privilege accounts that are not strictly required.
  • Consider replacing end-of-support or unpatched devices with hardware that receives active security maintenance if a fix is not released.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.