Skip to content
COOEY

FAIL › dossier

dir-823g firmware

PRODUCT

· dossier confidence 50%

D-Link's DIR-823G router firmware contained critical remote code execution and denial-of-service vulnerabilities in its HNAP1 protocol and firmware upload component, allowing attackers to execute arbitrary scripts and disrupt device operations.

PROFILE
CategoryNetworking HardwareWhat they doD-Link DIR-823G is a wireless router manufactured by D-Link.
SECURITY POSTURE

The DIR-823G firmware exhibited critical remote code execution and denial-of-service vulnerabilities in its HNAP1 protocol and firmware upload component, indicating severe flaws in command handling and input validation.

Notable failures
  • CVE-2020-25367: HNAP1 command injection RCE
  • CVE-2020-25368: HNAP1 command injection RCE
  • CVE-2020-25366: Firmware upload DoS
Patterns: critical unpatched command injection in proprietary protocols; insecure firmware upload mechanisms
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-04 CVE-2020-25367 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
2021-11-04 CVE-2020-25368 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
2021-11-04 CVE-2020-25366 critical An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
Open questions: D-Link's broader patching cadence for HNAP1 protocol vulnerabilities · Whether other D-Link firmware versions share the same HNAP1 command injection flaws
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:10:11.441845+00:00