cbcvebase.
CVE-2022-26258
published 2022-03-28

CVE-2022-26258: D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

PriorityP190critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
81.10%
99.6th percentile
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-820l_firmware

Detection & IOCsextracted from sources · hover to see the quote

ip159.203.15[.]179
domainvpn.komaru[.]today
urlhttp://159.203.15[.]179/wget.sh
urlhttp://159.203.15[.]179/wget.sh3
urlhttp://159.203.15[.]179/mips
urlhttp://159.203.15[.]179/mipsel
urlhttp://159.203.15[.]179/arm
urlhttp://159.203.15[.]179/arm5
urlhttp://159.203.15[.]179/arm6
urlhttp://159.203.15[.]179/arm7
urlhttp://159.203.15[.]179/sh4
urlhttp://159.203.15[.]179/arc
urlhttp://159.203.15[.]179/sparc
urlhttp://159.203.15[.]179/x86_64
urlhttp://159.203.15[.]179/i686
urlhttp://159.203.15[.]179/i586
hashB7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1
hash46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075
hash36DCAF547C212B6228CA5A45A3F3A778271FBAF8E198EDE305D801BC98893D5A
hash88B858B1411992509B0F2997877402D8BD9E378E4E21EFE024D61E25B29DAA08
hashD7564C7E6F606EC3A04BE3AC63FDEF2FDE49D3014776C1FB527C3B2E3086EBAB
hash72153E51EA461452263DBB8F658BDDC8FB82902E538C2F7146C8666192893258
hash7123B2DE979D85615C35FCA99FA40E0B5FBCA25F2C7654B083808653C9E4D616
hashCC3E92C52BBCF56CCFFB6F6E2942A676B3103F74397C46A21697B7D9C0448BE6
hash188BCE5483A9BDC618E0EE9F3C961FF5356009572738AB703057857E8477A36B
hash4567979788B37FBED6EEDA02B3C15FAFE3E0A226EE541D7A0027C31FF05578E2
hash06FC99956BD2AFCEEBBCD157C71908F8CE9DDC81A830CBE86A2A3F4FF79DA5F4
hash4BFF052C7FBF3F7AD025D7DBAB8BD985B6CAC79381EB3F8616BEF98FCB01D871
hash3B12ABA8C92A15EF2A917F7C03A5216342E7D2626B025523C62308FC799B0737
path/lan.asp
otherw5q6he3dbrsgmclkiu4to18npavj702f
other0x336699
  • CVE-2022-26258 exploits the DeviceName HTTP parameter in /lan.asp via command injection; monitor HTTP POST requests to /lan.asp on D-Link DIR-820L devices for unsanitized DeviceName values
  • Exploitation is delivered via HTTP POST to get set ccp on D-Link DIR-820L 1.05B03; monitor for POST requests to this endpoint
  • Upon successful exploitation, wget is used to download MooBot payloads from the malware host; detect outbound wget calls to 159.203.15[.]179 from D-Link devices
  • MooBot prints 'get haxored!' to console on execution; look for this string in process output or binary strings analysis
  • Palo Alto Networks Threat Prevention signatures 38600, 92960, 92959 and 92533 cover the exploit and MooBot activity
  • Check Point IPS signature 'D-Link DIR-820L Command Injection (CVE-2022-26258)' detects exploit traffic targeting this CVE
  • Downloaded MooBot binaries are renamed to 'Realtek' (by rt downloader) or 'Android' (by wget.sh downloader) after execution; hunt for these process/file names on compromised IoT devices
  • ·The C2 server vpn.komaru[.]today was offline at time of analysis; infrastructure may have rotated
  • ·The D-Link DIR-820L is end-of-life; no vendor patch will be issued and the device should be disconnected rather than patched

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.