HIGH

CVE-2022-40799

Dlink Dnr 322l Firmware 2022-11-29 CVSS v3.1
CVSS
8.8
KEV

Description

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

Summary dbcve.org

Command injection vulnerability in the Backup Config function of D-Link DNR-322L Network Video Recorder firmware versions 2.60B15 and below allows an authenticated attacker to inject and execute arbitrary OS-level commands through insufficient input validation of backup configuration parameters.

Mitigation

Apply available firmware patches; if no patch exists, enforce strict access controls, change default credentials, place device behind a firewall, and monitor for unauthorized access attempts.

Proof of Concept

Weakness (CWE)

CWE-494

EPSS Score

33.65%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE