Skip to content
COOEY

EXPOSURES › CVE-2022-26258

CVE-2022-26258

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26258 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatchedsupply-chain

D-Link DIR-820L exposed to RCE due to unpatched vulnerability

D-Link's DIR-820L router had an unpatched vulnerability in its /lan.asp endpoint that allowed remote code execution, linked to repeated RCE issues in D-Link's consumer firmware, posing a significant risk to CMMC environments.

Shame score — Repeated RCE vulnerabilities in D-Link's consumer firmware, poor security posture, and risk to CMMC environments.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.