CVE-2026-2143 | D-Link DIR-823X 250416 DDNS Service /goform/set_ddns ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd os command injection (EUVD-2026-5805 / WID-SEC-2026-0340)
A vulnerability classified as critical has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/set_ddns of the component DDNS Service. The manipulation of the argument ddnsType/ddnsDomainName/ddnsUserName/ddnsPwd leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-2143. The attack is possible to be carried out remotely. Moreover, an exploit is present.