Vulnerabilities > CVE-2025-1103 - NULL Pointer Dereference vulnerability in Dlink Dir-823X Firmware 240126/240802

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
dlink
CWE-476

Summary

A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of the file /goform/set_wifi_blacklists of the component HTTP POST Request Handler. The manipulation of the argument macList leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Vulnerable Configurations

Part Description Count
OS
Dlink
2
Hardware
Dlink
1

Common Weakness Enumeration (CWE)