Skip to content
COOEY

FAIL › dossier

dir-823g

PRODUCT

· dossier confidence 90%

The D-Link DIR-823G wireless router is a networking device with a critical security history of unpatched command injection vulnerabilities in its HNAP1 protocol and firmware upload component, enabling arbitrary script execution and denial of service attacks.

PROFILE
Categorynetworking hardwareWhat they doD-Link DIR-823G is a wireless router manufactured by D-Link.
SECURITY POSTURE

The device has a critical track record of unpatched command injection vulnerabilities in its HNAP1 protocol and firmware upload components, allowing arbitrary script execution and denial of service.

Notable failures
  • CVE-2020-25367: HNAP1 command injection RCE
  • CVE-2020-25368: HNAP1 command injection RCE
  • CVE-2020-25366: Firmware upload DoS
Patterns: repeated unpatched edge-device RCEs; insecure firmware upload mechanisms
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-04 CVE-2020-25367 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
2021-11-04 CVE-2020-25368 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
2021-11-04 CVE-2020-25366 critical An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:09:26.025027+00:00