CVE-2022-40799: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Other sources
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
D-Link DNR-322Lfrom your environment.Discontinue use of the product; decommission or remove D-Link DNR-322L devices running firmware versions <= 2.60B15.
- Compensating control
Apply mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40799?
CVE-2022-40799 has a severity rating of high due to its potential to allow authenticated attackers to execute OS level commands.
How do I fix CVE-2022-40799?
To fix CVE-2022-40799, upgrade the D-Link DNR-322L firmware to a version higher than 2.60B15.
Which devices are affected by CVE-2022-40799?
CVE-2022-40799 affects the D-Link DNR-322L firmware versions 2.60B15 and lower.
What type of vulnerability is CVE-2022-40799?
CVE-2022-40799 is classified as a data integrity failure that allows command execution.
Can CVE-2022-40799 be exploited remotely?
CVE-2022-40799 requires authentication, meaning an attacker must first gain access to the device to exploit it.