CVE-2025-11097
Last modified
CVE-2025-11097 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. EPSS estimates a 4.13% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in D-Link DIR-823X 250416. Impacted is an unknown function of the file /goform/set_device_name. The manipulation of the argument mac leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-823x Firmware | 250416 |
References
- https://github.com/n1ptune/dink/blob/main/set_device_name.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.326178Permissions Required, VDB Entry
- https://vuldb.com/?id.326178Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.661913Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11097?
How severe is CVE-2025-11097?
How do I fix CVE-2025-11097?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11091A security flaw has been discovered in Tenda AC21 up to 16.0…8.8
- CVE-2025-11092A weakness has been identified in D-Link DIR-823X 250416. Af…8.8
- CVE-2025-11093An arbitrary code execution vulnerability exists in multiple…7.2
- CVE-2025-11094A security vulnerability has been detected in code-projects …9.8
- CVE-2025-11095A vulnerability was detected in D-Link DIR-823X 250416. This…8.8
- CVE-2025-11096A flaw has been found in D-Link DIR-823X 250416. This issue …8.8
- CVE-2025-11098A vulnerability was found in D-Link DIR-823X 250416. The aff…8.8
- CVE-2025-11099A vulnerability was determined in D-Link DIR-823X 250416. Th…8.8
- CVE-2025-1110An issue has been discovered in GitLab CE/EE affecting all v…4.3
- CVE-2025-11100A vulnerability was identified in D-Link DIR-823X 250416. Th…8.8
- CVE-2025-11101A security flaw has been discovered in itsourcecode Open Sou…9.8
- CVE-2025-11102A weakness has been identified in Campcodes Online Learning …9.8
Are you affected by CVE-2025-11097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
