CVE-2025-10123: exploitation status and patch state

CVE-2025-10123 · CVSS 7.3 HIGH · EPSS 4%

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Is CVE-2025-10123 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2025-10123

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-15.