Vulnerability Details CVE-2025-10401
A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.9%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 6.5
Products affected by CVE-2025-10401
-
cpe:2.3:h:dlink:dir-823x:-
-
cpe:2.3:o:dlink:dir-823x_firmware:240126
-
cpe:2.3:o:dlink:dir-823x_firmware:240802