CVE-2022-26258

CRITICAL KEV

D-Link DIR-820L 1.05B03 - Remote Code Execution via HTTP POST to get set ccp

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-26258 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 8, 2022.

Description

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Scores

CVSS v3 9.8
EPSS 0.8716
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-09-08
VulnCheck KEV 2022-09-06
InTheWild.io 2022-09-06
ENISA EUVD EUVD-2022-30821
CWE
CWE-78
Status published
Products (1)
dlink/dir-820l_firmware 1.05b03
Published Mar 28, 2022
KEV Added Sep 08, 2022
Tracked Since Feb 18, 2026