CVE-2022-40799 is a critical data integrity failure in the 'Backup Config' feature of D-Link DNR-322L devices running firmware version 2.60B15 or earlier. This vulnerability allows an authenticated attacker to execute arbitrary OS-level commands on the device. With a CVSS score of 8.8 (HIGH), it is easily exploitable over the network with low privileges and no user interaction, leading to high impacts on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and a high EPSS score, despite a lack of public exploit code or significant media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.60b15CPE matchmatch criteria | cpe:2.3:o:dlink:dnr-322l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.