CVE-2022-26258criticalunder attackCWE-78

CVE-2022-26258

Published · Updated

80Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 9.8epss 92%
from disclosure to weapon
Published on NVDMar 27
CISA KEV+165d
exploitation probability
92%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-09-29

The impacted product is end-of-life and should be disconnected if still in use.

In short

A vulnerability in D-Link DIR-820L router version 1.05B03 allows attackers to execute arbitrary commands remotely through an unprotected HTTP POST request, potentially giving them full control of the device.

Technical detail

Remote command injection vulnerability in D-Link DIR-820L 1.05B03 accessible via HTTP POST to the 'get_set_ccp' endpoint without proper input validation or authentication. An attacker can inject OS commands that execute with device privileges, leading to complete system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a