CVE-2026-7067

HIGH

D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection

Title source: cna
STIX 2.1

Description

A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-359642 | D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection
https://vuldb.com/vuln/359642
Signature, Permissions Required signature permissions-required
VDB-359642 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/359642/cti
Third Party Advisory third-party-advisory
Submit #798645 | D-Link DIR822A_101 A_101 Buffer Overflow
https://vuldb.com/submit/798645
Product product
https://www.dlink.com/

Scores

CVSS v3 7.3
EPSS 0.0248
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-77
Status published
Products (2)
D-Link/DIR-822 A_101
dlink/dir-822_firmware 1.0.1
Published Apr 27, 2026
Tracked Since Apr 27, 2026