CVE-2026-4193

HIGH

D-Link DIR-823G goahead UpdateClientInfo access control

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/GetRouterInformationSettings/GetRouterLanSettings/GetWanSettings/SetAccessCtlList/SetAccessCtlSwitch/SetDeviceSettings/SetGuestWLanSettings/SetIPv4FirewallSettings/SetNetworkSettings/SetNetworkTomographySettings/SetNTPServerSettings/SetRouterLanSettings/SetStaticClientInfo/SetStaticRouteSettings/SetWLanRadioSecurity/SetWPSSettings/UpdateClientInfo of the component goahead. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (11)

Core 11
Core References
Product product
https://www.dlink.com/
Vdb Entry, Technical Description vdb-entry technical-description
VDB-351105 | D-Link DIR-823G goahead UpdateClientInfo access control
https://vuldb.com/?id.351105
Signature, Permissions Required signature permissions-required
VDB-351105 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/?ctiid.351105
Third Party Advisory third-party-advisory
Submit #769835 | D-Link 1.0.2B05 Improper Access Controls
https://vuldb.com/?submit.769835
Third Party Advisory third-party-advisory
Submit #769836 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate)
https://vuldb.com/?submit.769836
Third Party Advisory third-party-advisory
Submit #769837 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate)
https://vuldb.com/?submit.769837
Third Party Advisory third-party-advisory
Submit #769838 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate)
https://vuldb.com/?submit.769838
Third Party Advisory third-party-advisory
Submit #769839 | D-Link DIR823G 1.0.2B05 Stack-based Buffer Overflow (Duplicate)
https://vuldb.com/?submit.769839
Third Party Advisory third-party-advisory
Submit #769841 | D-Link DIR823G 1.0.2B05 Improper Access Controls (Duplicate)
https://vuldb.com/?submit.769841

Scores

CVSS v3 7.3
EPSS 0.0077
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (2)
D-Link/DIR-823G 1.0.2B05
dlink/dir-823g_firmware 1.0.2b05
Published Mar 16, 2026
Tracked Since Mar 16, 2026