CVE-2022-26258
dlink dir-820l firmware
Published 28 Mar 2022 · updated 9 Jul 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Sept 2022, with a remediation deadline of 29 Sept 2022 for US federal agencies.
Required action: The impacted product is end-of-life and should be disconnected if still in use.
Description
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
References
- github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0 · Broken Link, Exploit, Third Party Advisory
- github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.md · Exploit, Third Party Advisory
- www.dlink.com/en/security-bulletin/ · Not Applicable, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26258 · US Government Resource