CVE-2026-1544
A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of the argument lan_gateway results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
- Affected products
- Dir-823
- Dlink dir-823x Firmware
- = 250416
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 3.3% (87th percentile)
- Weakness
- CWE-77, CWE-78
- NVD status
- Analyzed
- Published
- 2026-01-28
CVE-2026-1544 at NVD
No indexed exploits for CVE-2026-1544 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-1544 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.