Junglewise Threat Intelligence

CVE-2022-40799: D-Link DNR-322L command execution in Backup Config

CVE-2022-40799 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-08-05

Technologies: D-Link DNR-322L. Vendors: D-Link.

Executive brief

The D-Link DNR-322L is a network video recorder used to manage and store security camera footage. A security flaw in the device's configuration backup feature allows an attacker to take full control of the system and execute unauthorized commands. Because this product is end-of-life, no official security patches are expected, and users are advised to stop using the device immediately to prevent potential data breaches or service disruptions.

Technical details

A vulnerability classified as CWE-494 (Download of Code Without Integrity Check) exists in the 'Backup Config' component of D-Link DNR-322L devices running firmware version 2.60B15 and earlier. The flaw stems from a failure to verify the integrity of data during configuration operations, which can be leveraged to achieve remote code execution. An authenticated attacker with network access can exploit this to execute arbitrary OS-level commands with high privileges. This vulnerability has been observed in the wild and is included in the CISA Known Exploited Vulnerabilities (KEV) catalog. As the device is end-of-life (EoL), users are encouraged to decommission the hardware.

Affected products

  • D-Link DNR-322L Firmware <= 2.60B15

Timeline

  • 2022-11-29: disclosed: Initial NVD publication
  • 2025-08-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog