CVE-2022-40799

9.5 CISA KEV

D-Link · DNR-322L

A data integrity failure in the Backup Config feature of D-Link DNR-322L firmware versions 2.60B15 and earlier allows an authenticated attacker to execute OS level commands on the device.

Executive summary

This critical vulnerability in the D-Link DNR-322L allows authenticated attackers to execute arbitrary OS commands and is currently being exploited in the wild.

Vulnerability

The device suffers from a data integrity failure within the Backup Config feature. An authenticated attacker can leverage this flaw to achieve remote OS level command execution on the target hardware.

Business impact

With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational security. Successful exploitation grants an attacker full control over the affected device, potentially leading to total system compromise, unauthorized data access, and lateral movement within the network. Given that the affected product is End-of-Life, the risk of unpatched exploitation is severe.

Remediation

Immediate Action: Because the device is End-of-Life and no patch is available, organizations should immediately disconnect affected D-Link DNR-322L units from the network and discontinue their use.

Proactive Monitoring: Monitor network traffic for unusual outbound connections or shell-related activity originating from the DNR-322L device to identify potential compromise.

Compensating Controls: If the device must remain operational, isolate it within a strictly segmented VLAN with no external network access, and restrict management interface access to authorized internal IP addresses only.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via GitHub and the researcher write-up referenced in the CVE record.

Analyst recommendation

Due to the critical severity, active exploitation in the wild, and the End-of-Life status of the D-Link DNR-322L, this device poses an unacceptable risk to the enterprise. Security teams must prioritize the immediate removal or complete network isolation of all affected units to prevent unauthorized access and potential system-wide compromise.

More D-Link CVEs

Sources