Aller au contenu

Fiche vulnérabilité

CVE-2025-10123 : faille critique dlink dir-823x firmware (CVSS 9.8)

Description

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
9 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • dlink dir-823x firmware

Références

Rechercher une autre vulnérabilité dans la base CVE