← Vulnerability feed

Vulnerability record · CVE-2022-40799 · published 29 November 2022

CVE-2022-40799: D-Link DNR-322L backup config command injection

Dlink · Dnr 322l Firmware

The 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authenticated attacker to run OS-level commands on the device. Because the device is a network video recorder, successful exploitation gives an attacker a foothold on a device that often sits on the same network as cameras and other trusted systems.

8.8 CVSS 3.1 High CISA KEV since 5 Aug 2025 EPSS 34% · top 1.7% CWE-494 · Download of code without integrity check
8.8CVSS 3.1 base score
34%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote OS command execution and is listed in CISA KEV with a public exploit, though it requires valid credentials and affects a specific end-of-life NVR model.

What it is

The 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authenticated attacker to run OS-level commands on the device. Because the device is a network video recorder, successful exploitation gives an attacker a foothold on a device that often sits on the same network as cameras and other trusted systems.

Impact

An authenticated attacker gains arbitrary OS command execution on the NVR, which can lead to full device compromise, data theft or use of the device as a pivot into the surrounding network.

Attack surface

The flaw is reachable over the network via the web management interface (CVSS vector AV:N/AC:L/PR:L/UI:N), so the attacker needs valid credentials but no user interaction. No other reachability details are given in the record.

Exploitation

CISA added this CVE to the KEV catalog on 2025-08-05 with a 2025-08-26 remediation due date, and a public exploit reference exists, indicating active exploitation. EPSS gives a 30-day probability of 0.3365 (98.3rd percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor's patch or mitigation for DNR-322L firmware if one is available; if not, discontinue use of the device as CISA advises.
  • Restrict network access to the NVR web interface to trusted management hosts only.
  • Change default and weak administrative credentials and enforce strong unique passwords.
  • Monitor the device for unexpected outbound connections or command execution activity.
  • Plan replacement of end-of-life DNR-322L units that no longer receive firmware updates.

Detection

  • Review NVR and web server logs for unusual requests to the 'Backup Config' endpoint, especially from unexpected source IPs.
  • Alert on new or unusual outbound network connections originating from the NVR.
  • Monitor for unexpected processes or command execution on the device where host-level telemetry is available.
  • Correlate authentication events on the NVR with subsequent configuration or backup actions for signs of abuse.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-40799 to the Known Exploited Vulnerabilities catalog on 5 August 2025 as "D-Link DNR-322L Download of Code Without Integrity Check Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 August 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-3272D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgiD-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'u…KEVEPSS 98%analysed9.8CVE-2024-3273D-Link legacy NAS command injection in nas_sharing.cgiAn unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS model…KEVEPSS 100%analysed8.7CVE-2024-7832Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS…EPSS 2.1%8.7CVE-2024-7831Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L…EPSS 1.8%8.7CVE-2024-7829Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS…EPSS 1.8%8.7CVE-2024-7830Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L…EPSS 1.8%8.7CVE-2024-7828Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,…EPSS 16%5.3CVE-2024-8212Dlink dns-315l firmware command injection vulnerabilityA vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2022-40799), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.