CVE-2022-40799
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 26 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.72% probability · 98th percentile
- CISA KEV
- Listed 5 August 2025 · due 26 August 2025
- Weakness
- CWE-494
- Affected
- dlink/dnr-322l firmware
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.dlink.com/uk/en/products/dnr-322l-cloud-network-video-recorder ; https://nvd.nist.gov/vuln/detail/CVE-2022-40799
References
- https://gitlab.com/lu-ka/cve-2022-40799Exploit, Third Party Advisory
- https://gitlab.com/lu-ka/cve-2022-40799Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40799US Government Resource
- https://www.dlink.com/uk/en/products/dnr-322l-cloud-network-video-recorderProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.