EXPOSURES › CVE-2022-26258
CVE-2022-26258
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatchedsupply-chain
D-Link DIR-820L exposed to RCE due to unpatched vulnerability
D-Link's DIR-820L router had an unpatched vulnerability in its /lan.asp endpoint that allowed remote code execution, linked to repeated RCE issues in D-Link's consumer firmware, posing a significant risk to CMMC environments.
Shame score — Repeated RCE vulnerabilities in D-Link's consumer firmware, poor security posture, and risk to CMMC environments.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.