CVE-2026-2210
Published: 09 February 2026
Summary
CVE-2026-2210 is a high-severity Command Injection (CWE-77) vulnerability in Dlink Dir-823X Firmware. Its CVSS base score is 7.2 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 33.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Threat & Defense at a Glance
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
OS command injection in public-facing router web endpoint directly enables remote exploitation of the device (T1190) and arbitrary Unix shell command execution (T1059.004).
NVD Description
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and…
more
may be used.
Deeper analysisAI
CVE-2026-2210 is an OS command injection vulnerability (CWE-77, CWE-78) discovered in D-Link DIR-823X routers running firmware version 250416. The flaw resides in the sub_4211C8 function of the /goform/set_filtering file, where improper input handling allows attackers to inject and execute arbitrary operating system commands.
The vulnerability carries a CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating network accessibility, low attack complexity, and no requirement for user interaction, though it demands high privileges such as administrative access. A privileged remote attacker could exploit this to execute arbitrary commands, resulting in high impacts to confidentiality, integrity, and availability, potentially leading to full device compromise.
Advisories referenced in VulDB and GitHub detail the issue, with a public proof-of-concept exploit available, including a ZIP file demonstrating remote command injection via /goform/set_filtering. No vendor patches are specified in the available references.
The exploit has been disclosed publicly as of the CVE publication on 2026-02-09 and may be actively used by attackers.
Details
- CWE(s)