Vulnerability Description
A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-823X Firmware | 250416 |
| Dlink | Dir-823X | All versions |
Related Weaknesses (CWE)
References
- https://github.com/n1ptune/dink/blob/main/uci_del_in_delete_prohibiting.mdExploitThird Party Advisory
- https://vuldb.com/?ctiid.326180Permissions RequiredVDB Entry
- https://vuldb.com/?id.326180Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.661916Third Party AdvisoryVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2025-11099?
CVE-2025-11099 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue causes command...
How severe is CVE-2025-11099?
CVE-2025-11099 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11099?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-823X Firmware, Dlink Dir-823X.