CVE-2025-2717 | D-Link DIR-823X 240126/240802 HTTP POST Request /goform/diag_nslookup sub_41710C target_addr os command injection
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os command injection.
The identification of this vulnerability is CVE-2025-2717. The attack may be initiated remotely. Furthermore, there is an exploit available.