Back

CRITICAL

DLINK - DSL-224 Post-auth RCE.

Published Nov 17, 2022

Description

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

Affected products

Remediation

Vendor solution

Update to version 3.0.9_Beta Hotfix

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCD
Published Nov 17, 2022
Updated Apr 29, 2025
Reserved Jul 26, 2022
CISA Vulnrichment
Updated Apr 29, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCD
Published Nov 17, 2022
Updated Apr 29, 2025
Exploited since n/a
EUVD-2022-39486