CVE-2026-7067
7.3D-Link · DIR-822
A command injection vulnerability in the D-Link DIR-822 DHCP service allows remote, unauthenticated attackers to execute arbitrary system commands via the Hostname parameter.
Executive summary
The D-Link DIR-822 router is vulnerable to remote command injection, which allows unauthenticated attackers to execute arbitrary code on the device.
Vulnerability
This vulnerability is a command injection flaw (CWE-77) located in the system function of the udhcpd DHCP service. An unauthenticated attacker can trigger this by sending a malicious Hostname argument to the device.
Business impact
The exploitation of this vulnerability permits unauthorized code execution on the router, which can lead to complete device compromise, unauthorized network access, and interception of local traffic. Given the CVSS score of 7.3, this represents a high risk to network integrity, especially as it allows remote access without requiring any user authentication.
Remediation
Immediate Action: As the affected hardware is no longer supported by the manufacturer, the primary remediation is to decommission the device or replace it with a currently supported model.
Proactive Monitoring: Network administrators should monitor traffic for unusual DHCP handshake patterns or unexpected outbound connections originating from the router management interface.
Compensating Controls: If immediate replacement is not possible, isolate the affected router on a restricted network segment and disable the DHCP service if the device functionality allows, though this will not fully eliminate the risk of hardware-level compromise.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the vulnerability researcher.
Analyst recommendation
Due to the end-of-life status of the D-Link DIR-822 and the presence of a functional proof-of-concept, this device poses an unacceptable risk to any network environment. Organizations should prioritize the immediate retirement of this hardware to prevent potential remote exploitation.
More D-Link CVEs
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-359642 | D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection Vulnerability database entry
- VDB-359642 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #798645 | D-Link DIR822A_101 A_101 Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com