VulnerabilityAnalyzed
CVE-2026-1685
A vulnerability was identified in D-Link DIR-823X 250416.
LOW 2.9EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit is publicly available and might be used.
- CVSS 4.0
- 2.9 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-307, CWE-799
- Affected
- dlink/dir-823x firmware
- Source
- cna@vuldb.com
References
- https://github.com/master-abc/cve/issues/17Issue Tracking
- https://vuldb.com/?ctiid.343479Permissions Required, VDB Entry
- https://vuldb.com/?id.343479Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.740886Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.