LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26258: D-Link DIR-820L Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26258 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.

CVE-2022-26258 is a remote code execution vulnerability affecting the D-Link DIR-820L router. It involves an unspecified flaw in the Device Name parameter of the /lan.asp endpoint that can allow an attacker to execute code on the device. Because this product is end-of-life, the issue matters for any organization still running these units on production or home-office networks: a successful exploit can give an attacker control of the router and a foothold into the attached network.

Defenders should treat any remaining DIR-820L devices as high priority for removal rather than relying on a patch that may never arrive. Confirm all technical details against the vendor advisory and CISA guidance before acting.

How it works

The vulnerability is classified as CWE-78 (OS Command Injection). In this class of flaw, user-controlled input is passed to a system command without proper sanitization. According to the CISA summary, the Device Name parameter in /lan.asp on the D-Link DIR-820L can be abused to achieve remote code execution. An attacker who can reach the vulnerable interface—typically over the local network or, if the management interface is exposed, from the internet—can inject commands that the device then runs with the privileges of the web service or underlying process.

Exact exploit mechanics, required authentication, or payload formats are not specified in the available facts; treat any public proof-of-concept material with caution and verify behavior only in a controlled lab. The practical outcome is that an attacker can run arbitrary commands on the router, potentially altering configuration, installing persistence, or pivoting to other hosts.

Am I affected? How to find it in your systems

The D-Link DIR-820L is a consumer and small-office wireless router. It commonly appears in branch offices, remote-worker homes, labs, and any environment that still uses older D-Link hardware. Because the product is end-of-life, no ongoing security support is expected.

If the device is present, assume it is vulnerable until proven otherwise and confirm the exact firmware state against the vendor advisory.

How to remediate

The CISA required action is clear: the impacted product is end-of-life and should be disconnected if still in use. There is no indication of a supported patch path for this model.

After replacement, verify that no residual management interfaces or port-forwarding rules still point to the old device.

If you can't patch immediately

Because the product is end-of-life, the only durable remediation is disconnection. Until that can be completed, apply compensating controls to reduce exposure:

These steps only buy time; schedule the physical removal of the device as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on network devices can lead to broader breaches, including credential theft, lateral movement, and data exfiltration. Known ransomware use of this specific CVE is not documented. If the DIR-820L was reachable from untrusted networks or showed signs of compromise, treat connected systems as potentially exposed: rotate credentials, review authentication logs, and check for unauthorized accounts or persistence. You can run a free exposure scan of your email addresses against known breach data to determine whether any associated accounts appear in public breach corpora and take further action accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DIR-820L
WeaknessCWE-78
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities