LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-40799: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 5, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 26, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-40799 to its Known Exploited Vulnerabilities catalog on Aug 5, 2025, with a federal patch deadline of Aug 26, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be…

CVE-2022-40799 is a download-of-code-without-integrity-check flaw in the D-Link DNR-322L network video recorder. An authenticated attacker can abuse it to run operating-system-level commands on the device. Because the product may already be end-of-life or end-of-service, the practical risk is elevated: unpatched units remain reachable on many networks and can serve as a foothold into the rest of the environment.

Defenders should treat any remaining DNR-322L appliances as high-priority inventory items. Confirm exact impact and any available guidance against the vendor advisory and CISA’s published summary before deciding on next steps.

How it works

The vulnerability is classified as CWE-494: Download of Code Without Integrity Check. In this class of flaw, the device accepts and executes code or firmware that has not been cryptographically verified for authenticity or integrity. An attacker who already holds valid credentials on the DNR-322L can supply a malicious payload that the device treats as legitimate. Once the payload runs, the attacker gains the ability to issue OS-level commands, potentially taking full control of the recorder.

No public exploit mechanics beyond this high-level description are provided here; teams must consult the vendor advisory for any additional technical detail. The key defensive takeaway is that authentication alone is insufficient protection when the integrity of downloaded code is never checked.

Am I affected? How to find it in your systems

The only product named in the public record is the D-Link DNR-322L. These appliances typically sit on local networks as network video recorders, often with web management interfaces exposed to administrators and sometimes to broader subnets. Inventory steps:

Because the product may be end-of-life, version numbers alone may not indicate a safe state; treat every discovered unit as potentially vulnerable until the vendor advisory is reviewed. Look for anomalous administrative logins, unexpected firmware-update events, or command-execution artifacts in device logs if those logs are still being collected. Telemetry from network sensors that flag unusual outbound connections from NVR IP addresses can also surface post-exploitation activity.

How to remediate

CISA’s required action is clear: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-connected services, or discontinue use of the product if mitigations are unavailable. Given the explicit note that impacted products could be end-of-life or end-of-service, the most reliable remediation for most organizations is to retire the DNR-322L entirely and replace it with a supported recorder.

If the vendor has published a firmware update or configuration change that addresses CWE-494, apply it immediately and verify the new image hash against the advisory. After any update, re-inventory the device to confirm the change took effect. Document the retirement or upgrade decision so that future audits can demonstrate compliance.

If you can't patch immediately

When immediate replacement is not feasible, reduce the attack surface with compensating controls:

These measures do not eliminate the underlying integrity-check weakness; they only buy time until the device can be removed.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to broader network compromise and data exposure. If you discover that a DNR-322L was reachable by an attacker, assume that any credentials, video footage, or adjacent systems that the device could reach may have been accessed. Review authentication logs, camera storage, and connected hosts for signs of lateral movement. As a quick additional check, you can run a free exposure scan of your organizational email addresses against known breach data sets to determine whether any related accounts already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DNR-322L
WeaknessCWE-494
Added to CISA KEVAug 5, 2025
Federal patch deadlineAug 26, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities