CVE-2025-2359 | D-Link DIR-823G 1.0.2B05_20181207 DDNS Service /HNAP1/ SetDDNSSettings SOAPAction improper authorization
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-2359. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.