CVE detail
CVE-2025-11096
A flaw has been found in D-Link DIR-823X 250416. This issue affects some unknown processing of the file /goform/diag_traceroute. Executing manipulation of the argument target_addr can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.dlink.com/www.dlink.com
No excerpt available.
Vendor Advisorywww.dlink.comSep 28, 2025, 5:15 AM - https://vuldb.com/?submit.661912vuldb.com
No excerpt available.
Exploitvuldb.comSep 28, 2025, 5:15 AM - https://vuldb.com/?id.326177vuldb.com
No excerpt available.
Exploitvuldb.comSep 28, 2025, 5:15 AM - https://vuldb.com/?ctiid.326177vuldb.com
No excerpt available.
Exploitvuldb.comSep 28, 2025, 5:15 AM No excerpt available.
Exploitgithub.comSep 28, 2025, 5:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- n1ptune/dinkHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 23, 2026, 6:20 AM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-1125CVSS 5.5 · Medium
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of t…
- CVE-2025-14208CVSS 2.1 · Low
A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument…
- CVE-2025-11100CVSS 2.1 · Low
A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection.…
- CVE-2025-11099CVSS 2.1 · Low
A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument de…
- CVE-2025-11098CVSS 2.1 · Low
A vulnerability was found in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList…
- CVE-2025-11097CVSS 2.1 · Low
A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to comman…