Junglewise Threat Intelligence

CVE-2022-26258: D-Link DIR-820L Remote Code Execution Vulnerability

CVE-2022-26258 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-09-08

Vendors: D-Link.

Executive brief

D-Link DIR-820L devices contain a remote command execution (RCE) vulnerability via an HTTP POST request to the 'get set ccp' function. The flaw allows an unauthenticated attacker to execute arbitrary OS commands on the device.

Affected products

  • D-Link DIR-820L firmware 1.05B03
  • D-Link DIR-820L

Timeline

  • 2022-09-08: disclosed
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog