HIGH
CVE-2022-40799
CVSS
8.8
KEV
Description
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
Summary dbcve.org
Command injection vulnerability in the Backup Config function of D-Link DNR-322L Network Video Recorder firmware versions 2.60B15 and below allows an authenticated attacker to inject and execute arbitrary OS-level commands through insufficient input validation of backup configuration parameters.
Mitigation
Apply available firmware patches; if no patch exists, enforce strict access controls, change default credentials, place device behind a firewall, and monitor for unauthorized access attempts.
Weakness (CWE)
CWE-494
EPSS Score
33.65%
Probability of exploitation in next 30 days
98.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.