CVE-2026-2142
As of 2026-02-10, CVE-2026-2142 is a CVSS 7.2 (HIGH-severity) vulnerability. EPSS exploitation probability 0.1%. Threadlinqs Intelligence tracks 1 threat exploiting it.
Last updated: 2026-02-10
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-77, CWE-78
Threats tracking this CVE
References
- https://github.com/master-abc/cve/issues/29
- https://vuldb.com/?ctiid.344777
- https://vuldb.com/?id.344777
- https://vuldb.com/?submit.747428
- https://www.dlink.com/
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.