CVE-2025-10814

A

vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dlink:dir-823x_firmware:240126:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-823x_firmware:240802:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-823x_firmware:250416:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-823x:*:*:*:*:*:*:*:*

History

24 Sep 2025, 18:42

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 21:15

Updated : 2025-09-24 18:42


NVD link : CVE-2025-10814

Mitre link : CVE-2025-10814

CVE.ORG link : CVE-2025-10814


JSON object : View

Products Affected
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')