CVE-2022-26258 is a critical Remote Command Execution (RCE) vulnerability affecting D-Link DIR-820L routers running firmware version 1.05B03, allowing unauthenticated attackers to execute arbitrary commands via an HTTP POST request to the get_set_ccp endpoint. With a CVSS score of 9.8 (Critical), this vulnerability requires no user interaction and can lead to complete compromise of confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and mentions in media coverage regarding the Moobot botnet. Despite no public Metasploit or ExploitDB modules, community discussions and GitHub repositories indicate readily available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.05b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-820l_firmware:1.05b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.