Vulnerability record · CVE-2022-26258 · published 28 March 2022
CVE-2022-26258: D-Link DIR-820L router OS command injection via HTTP POST
Dlink · Dir 820l Firmware
D-Link DIR-820L firmware 1.05B03 contains an OS command injection flaw reachable through an HTTP POST request to the set ccp handler, allowing remote command execution. The device is end-of-life, so no firmware fix is expected and exposed units remain permanently at risk.
Description
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, active KEV listing, and near-certain EPSS score on an end-of-life device with no patch path.
What it is
D-Link DIR-820L firmware 1.05B03 contains an OS command injection flaw reachable through an HTTP POST request to the set ccp handler, allowing remote command execution. The device is end-of-life, so no firmware fix is expected and exposed units remain permanently at risk.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the router, gaining full control of the device and its network position.
Attack surface
Reachable over the network via HTTP POST to the set ccp endpoint; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Listed in CISA KEV since 2022-09-08 with a required action to disconnect the end-of-life product, and EPSS shows a 30-day probability of 0.91981 (99.8th percentile); public exploit references are tagged Exploit.
What to do
- No patch is available because the product is end-of-life; replace the DIR-820L or remove it from service.
- If replacement is not immediate, disconnect the device from the internet and restrict management access to a trusted internal segment.
- Disable remote administration and any WAN-facing HTTP management interface.
- Segment or isolate any remaining units so a compromised router cannot reach other internal assets.
- Inventory for DIR-820L units still deployed and track them for decommissioning.
Detection
- Monitor HTTP POST requests to the set ccp handler on DIR-820L management interfaces for command-injection patterns.
- Alert on unexpected outbound connections or new listening services originating from router management addresses.
- Review router logs and network flow data for anomalous command execution or shell activity tied to the device.
- Scan internal networks for DIR-820L management interfaces exposed beyond their intended segment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-26258 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "D-Link DIR-820L Remote Code Execution Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 29 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0 | Broken LinkExploitThird Party Advisory |
| https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_e | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Not ApplicableVendor Advisory |
| https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0 | Broken LinkExploitThird Party Advisory |
| https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_e | ExploitThird Party Advisory |
| https://www.dlink.com/en/security-bulletin/ | Not ApplicableVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26258 | US Government Resource |
Track CVE-2022-26258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26258), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.