CVE-2022-36786: DLINK - DSL-224 Post-auth RCE.
DLINK - DSL-224 Post-auth PCE. DLINK router has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
Other sources
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36786?
CVE-2022-36786 has a high severity rating due to its potential for remote code execution with ROOT permissions.
How do I fix CVE-2022-36786?
To fix CVE-2022-36786, ensure your D-Link DSL-224 firmware is updated to the latest patched version provided by the manufacturer.
What kind of attack does CVE-2022-36786 allow?
CVE-2022-36786 allows for post-authentication remote code execution through the router's NTP server configuration interface.
Who is affected by CVE-2022-36786?
Users of the D-Link DSL-224 router are affected by CVE-2022-36786 if they are running vulnerable versions of the firmware.
Is my D-Link DSL-224 router vulnerable if it’s not using JSON-RPC API?
Yes, CVE-2022-36786 exploits the JSON-RPC API for configuration, so if your router uses this interface, it remains vulnerable regardless of your API usage.