Vulnerability record · CVE-2022-40799 · published 29 November 2022
CVE-2022-40799: D-Link DNR-322L backup config command injection
Dlink · Dnr 322l Firmware
The 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authenticated attacker to run OS-level commands on the device. Because the device is a network video recorder, successful exploitation gives an attacker a foothold on a device that often sits on the same network as cameras and other trusted systems.
Description
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote OS command execution and is listed in CISA KEV with a public exploit, though it requires valid credentials and affects a specific end-of-life NVR model.
What it is
The 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authenticated attacker to run OS-level commands on the device. Because the device is a network video recorder, successful exploitation gives an attacker a foothold on a device that often sits on the same network as cameras and other trusted systems.
Impact
An authenticated attacker gains arbitrary OS command execution on the NVR, which can lead to full device compromise, data theft or use of the device as a pivot into the surrounding network.
Attack surface
The flaw is reachable over the network via the web management interface (CVSS vector AV:N/AC:L/PR:L/UI:N), so the attacker needs valid credentials but no user interaction. No other reachability details are given in the record.
Exploitation
CISA added this CVE to the KEV catalog on 2025-08-05 with a 2025-08-26 remediation due date, and a public exploit reference exists, indicating active exploitation. EPSS gives a 30-day probability of 0.3365 (98.3rd percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor's patch or mitigation for DNR-322L firmware if one is available; if not, discontinue use of the device as CISA advises.
- Restrict network access to the NVR web interface to trusted management hosts only.
- Change default and weak administrative credentials and enforce strong unique passwords.
- Monitor the device for unexpected outbound connections or command execution activity.
- Plan replacement of end-of-life DNR-322L units that no longer receive firmware updates.
Detection
- Review NVR and web server logs for unusual requests to the 'Backup Config' endpoint, especially from unexpected source IPs.
- Alert on new or unusual outbound network connections originating from the NVR.
- Monitor for unexpected processes or command execution on the device where host-level telemetry is available.
- Correlate authentication events on the NVR with subsequent configuration or backup actions for signs of abuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-40799 to the Known Exploited Vulnerabilities catalog on 5 August 2025 as "D-Link DNR-322L Download of Code Without Integrity Check Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 August 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/lu-ka/cve-2022-40799 | ExploitThird Party Advisory |
| https://gitlab.com/lu-ka/cve-2022-40799 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40799 | US Government Resource |
| https://www.dlink.com/uk/en/products/dnr-322l-cloud-network-video-recorder | Product |
Track CVE-2022-40799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-40799), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.