CVE-2025-10034 is a critical buffer overflow vulnerability in D-Link DIR-825 firmware version 1.08.01, specifically within the get_ping6_app_stat function of the ping6_response.cg component. This flaw allows for remote, unauthenticated attackers to execute arbitrary code or cause a denial of service by manipulating the ping6_ipaddr argument. With a CVSS score of 9.8 and a FAUCET Risk Score of 95/100, the vulnerability poses a severe risk, leading to potential complete compromise of confidentiality, integrity, and availability. A public exploit is available, and while not currently in CISA's KEV catalog, community discussion highlights the immediate need for mitigation, especially given that affected products are End-of-Life (EOL) and will not receive patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.08.01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-825_firmware:1.08.01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.