Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29841 | A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. |
Wed, 24 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-823x:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:250416:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dir-823x Dlink dir-823x Firmware |
Thu, 18 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dir-823x |
|
| Vendors & Products |
D-link
D-link dir-823x |
Thu, 18 Sep 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Title | D-Link DIR-823X Environment Variable goahead sub_412E7C command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-18T13:18:03.415Z
Reserved: 2025-09-17T12:23:57.015Z
Link: CVE-2025-10634
Updated: 2025-09-18T13:17:52.027Z
Status : Analyzed
Published: 2025-09-18T02:15:40.273
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-10634
No data.
OpenCVE Enrichment
Updated: 2025-09-18T12:41:04Z
EUVD