PT-2025-36565 · D Link · Dir-823

Qmssdxn

·

Published

2025-09-02

·

Updated

2025-09-14

·

CVE-2025-10123

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-823X versions up to 250416
Description A vulnerability exists in D-Link DIR-823X routers that allows for remote command injection. The vulnerability is located in the sub 415028 function of the /goform/set static leases file. Manipulation of the Hostname argument can lead to command injection, potentially granting unauthenticated attackers full device control. The exploit for this issue has been publicly disclosed.
Recommendations D-Link DIR-823X versions up to 250416: Update the firmware to address the vulnerability. D-Link DIR-823X versions up to 250416: Disable WAN administration access. D-Link DIR-823X versions up to 250416: Restrict management access to the LAN.

Exploit

Fix

RCE

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-11534
CVE-2025-10123

Affected Products

Dir-823