CVE-2022-40799

Published Nov 29, 2022

Last updated 14 hours ago

Overview

Description
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
Exploit added on
Aug 5, 2025
Exploit action due
Aug 26, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-494
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-494

Social media

Hype score
Not currently trending

Configurations