🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

D-Link DIR-823X Command Injection RCE (CVE-2025-29635) | MSSP Advisory

High🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2025-29635
CVSS Score7.2
Affecteddir-823x_firmware, dir-823x
📋Executive Summary
CISA added CVE-2025-29635 to the Known Exploited Vulnerabilities catalog, flagging a command injection flaw in D-Link DIR-823X routers that lets attackers execute arbitrary commands via authenticated POST requests. The product is likely end-of-life with no patches coming, and CISA is telling organizations to discontinue use entirely.
⚠️Why It Matters for MSSPs
Your clients probably have these routers sitting in branch offices, home offices, or small sites where they provide network access to business systems. If compromised, an attacker gains a foothold inside the network perimeter that your monitoring tools might miss, and your client will ask why you never warned them about end-of-life networking gear.
Recommended Action
Run network discovery scans across all client environments within 24 hours to identify D-Link DIR-823X devices and create a replacement timeline for each instance. Contact clients immediately with findings and position this as a critical infrastructure upgrade that cannot wait for the next refresh cycle.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.