CVE-2025-10634: D-Link DIR-823X Firmware
High severity, CVSS 8.8. EPSS: 7.4% chance of exploitation in the next 30 days.
A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected products
- D-Link DIR-823X Firmware: version 240126 only; version 240802 only; version 250416 only
Published 2025-09-18. Last modified 2026-09-30.