CRITICAL
DLINK - DSL-224 Post-auth RCE.
Published Nov 17, 2022
9.9
CRITICALCVSS 3.1
EPSS 0.91%
Description
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
Affected products
-
- Version All versionsStatusaffectedConstraints<Update to version 3.0.9_Beta Hotfix
- Version
AND
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to version 3.0.9_Beta Hotfix
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-39486 Advisory
- https://www.gov.il/en/Departments/faq/cve_advisories Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-39486 | Advisory | |
| https://www.gov.il/en/Departments/faq/cve_advisories | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCD
Published Nov 17, 2022
Updated Apr 29, 2025
Reserved Jul 26, 2022
Link CVE-2022-36786
CISA Vulnrichment
Updated Apr 29, 2025
ENISA EUVD
EUVD-2022-39486 Assigner INCD
Published Nov 17, 2022
Updated Apr 29, 2025
Exploited since n/a
Link EUVD-2022-39486