6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Basic Information
ID
CVE-2025-10123
Source
VulDB
Published
Sep 9, 2025 at 02:32
Affected Product
Vendor
D-Link
Product
DIR-823X
Version
250416
Affected Versions
D-Link DIR-823X 250416
CWE Classification
References
- vuldb.com /
- vuldb.com /
- vuldb.com /
- github.com /lin-3-start/lin-cve/blob/main/DIR-823X/D-Link%20DIR-823X%20routers%20have%20an%20unauthorized%20command%20execution%20vulnerability.md
- github.com /lin-3-start/lin-cve/blob/main/DIR-823X/D-Link%20DIR-823X%20routers%20have%20an%20unauthorized%20command%20execution%20vulnerability.md
- www.dlink.com /