PT-2025-36565 · D Link · Dir-823

·

CVE-2025-10123

·

Published

2025-09-02

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X versions prior to 250416
Description A command injection issue exists in the sub 415028 function within the /goform/set static leases endpoint. The flaw is caused by insufficient input validation of the Hostname variable. A remote attacker can exploit this by sending a specially crafted request to execute arbitrary commands on the device, potentially gaining full control.
Recommendations Update the firmware to a version newer than 250416. Disable WAN administration. Restrict management access to the local area network (LAN).

Exploit

Fix

RCE

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11534
CVE-2025-10123

Affected Products

Dir-823