CVE-2022-26258: D-Link DIR-820L Remote Code Execution Vulnerability
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
Other sources
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect the D-Link DIR-820L device (version 1.05B03) if it is still in use, since the product is end-of-life and contains a remote code execution vulnerability accessible via HTTP POST to /lan.asp (Device Name parameter / get set ccp).
Event History
Frequently Asked Questions
What is CVE-2022-26258?
CVE-2022-26258 is a remote code execution vulnerability in the D-Link DIR-820L router.
How severe is CVE-2022-26258?
CVE-2022-26258 has a severity rating of 9.8 (critical).
What is the affected software by CVE-2022-26258?
The D-Link DIR-820L router firmware version 1.05-b03 is affected by CVE-2022-26258.
How can an attacker exploit CVE-2022-26258?
An attacker can exploit CVE-2022-26258 by sending malicious input to the Device Name parameter in /lan.asp, which triggers remote code execution.
Is there a fix for CVE-2022-26258?
It is recommended to update to a fixed firmware version provided by D-Link to mitigate the vulnerability.