CVE-2022-40799
Last modified
CVE-2022-40799 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.. CISA has confirmed active exploitation in the wild. EPSS estimates a 31.33% chance of exploitation in the next 30 days.
Description
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dnr-322l Firmware | <= 2.60b15 |
References
- https://gitlab.com/lu-ka/cve-2022-40799Exploit, Third Party Advisory
- https://gitlab.com/lu-ka/cve-2022-40799Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40799US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-40799?
How severe is CVE-2022-40799?
How do I fix CVE-2022-40799?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-4078Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40784Unlimited strcpy on user input when setting a locale file le…8.8
- CVE-2022-40785Unsanitized input when setting a locale file leads to shell …8.8
- CVE-2022-4079Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40797Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar …9.8
- CVE-2022-40798OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Thr…7.5
- CVE-2022-4080Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-40805The d8s-urls for python 0.1.0, as distributed on PyPI, inclu…9.8
- CVE-2022-40806The d8s-uuids for python, as distributed on PyPI, included a…9.8
- CVE-2022-40807The d8s-domains for python, as distributed on PyPI, included…9.8
- CVE-2022-40808The d8s-dates for python, as distributed on PyPI, included a…9.8
- CVE-2022-40809The d8s-dicts for python, as distributed on PyPI, included a…9.8
Are you affected by CVE-2022-40799?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
