CVE-2025-10634

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Configurations

No configuration.

History

18 Sep 2025, 14:15

Type Values Removed Values Added
References () https://github.com/Cpppq43/D-Link/blob/main/DIink-DIR-823x.md - () https://github.com/Cpppq43/D-Link/blob/main/DIink-DIR-823x.md -

18 Sep 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-18 02:15

Updated : 2025-09-18 14:15


NVD link : CVE-2025-10634

Mitre link : CVE-2025-10634

CVE.ORG link : CVE-2025-10634


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')