CVE-2022-26258
published 2022-03-28CVE-2022-26258: D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
PriorityP190critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-09-29
Exploited in the wild
EPSS
81.10%
99.6th percentile
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-820l_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-26258 exploits the DeviceName HTTP parameter in /lan.asp via command injection; monitor HTTP POST requests to /lan.asp on D-Link DIR-820L devices for unsanitized DeviceName values ↗
- →Exploitation is delivered via HTTP POST to get set ccp on D-Link DIR-820L 1.05B03; monitor for POST requests to this endpoint ↗
- →Upon successful exploitation, wget is used to download MooBot payloads from the malware host; detect outbound wget calls to 159.203.15[.]179 from D-Link devices ↗
- →MooBot prints 'get haxored!' to console on execution; look for this string in process output or binary strings analysis ↗
- →Palo Alto Networks Threat Prevention signatures 38600, 92960, 92959 and 92533 cover the exploit and MooBot activity ↗
- →Check Point IPS signature 'D-Link DIR-820L Command Injection (CVE-2022-26258)' detects exploit traffic targeting this CVE ↗
- →Downloaded MooBot binaries are renamed to 'Realtek' (by rt downloader) or 'Android' (by wget.sh downloader) after execution; hunt for these process/file names on compromised IoT devices ↗
- ·The C2 server vpn.komaru[.]today was offline at time of analysis; infrastructure may have rotated ↗
- ·The D-Link DIR-820L is end-of-life; no vendor patch will be issued and the device should be disconnected rather than patched ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qf97-3r3x-x56v: D-Link DIR-820L 1
ghsa_unreviewed·2022-03-29
CVE-2022-26258 [CRITICAL] CWE-78 GHSA-qf97-3r3x-x56v: D-Link DIR-820L 1
D-Link DIR-820L 1.05B03 was discovered to contain a remote command execution (RCE) vulnerability via the Device Name parameter in /lan.asp.
VulnCheck
D-Link DIR-820L Remote Code Execution Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-26258 [CRITICAL] CWE-78 D-Link DIR-820L Remote Code Execution Vulnerability
D-Link DIR-820L Remote Code Execution Vulnerability
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
Affected: D-Link DIR-820L
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://unit42.paloaltonetworks.com/moobot-d-link-devices/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.forescout.com/blog/doj-moobot-botnet-commandeered-by-russian-apt28-analysis-of-attacks-against-routers-and-malware-samples/
Remediation Due: 2022-09-29
CISA
D-Link DIR-820L Remote Code Execution Vulnerability
cisa·2022-09-08·CVSS 9.8
CVE-2022-26258 [CRITICAL] CWE-78 D-Link DIR-820L Remote Code Execution Vulnerability
Vulnerability: D-Link DIR-820L Remote Code Execution Vulnerability
Affected: D-Link DIR-820L
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10295; https://nvd.nist.gov/vuln/detail/CVE-2022-26258
Remediation Due Date: 2022-09-29
No detection rules found.
No public exploits indexed.
Checkpoint
12th September – Threat Intelligence Report
blogs_checkpoint·2022-09-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] 12th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 12th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 12th September, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research uncovered a malicious campaign dubbed “DangerousSavanna” targeting multiple major financial groups in French-speaking Africa for the past two years. Threat actors used spear-phishing as the initial infection method, sending malicious attachments by emails to financial services employees in Ivory C
Unit42
Mirai Variant MooBot Targeting D-Link Devices
blogs_unit42·2022-09-06·CVSS 9.8
CVE-2015-2051 [CRITICAL] Mirai Variant MooBot Targeting D-Link Devices
## Executive Summary
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link, a company that specializes in network and connectivity products. The vulnerabilities exploited include:
- CVE-2015-2051: D-Link HNAP SOAPAction Header Command Execution Vulnerability
- CVE-2018-6530: D-Link SOAP Interface Remote Code Execution Vulnerability
- CVE-2022-26258: D-Link Remote Command Execution Vulnerability
- CVE-2022-28958: D-Link Remote Command Execution Vulnerability
If the devices are compromised, they will be fully controlled by attackers, who could utilize those devices to conduct further attacks such as distributed denial-of-service (DDoS) attacks. The exploit attempts captured by Unit 42 researchers leverage the aforementioned vu
Unit42
Mirai Variant MooBot Targeting D-Link Devices
blogs_unit42·2022-09-06·CVSS 9.8
CVE-2015-2051 [CRITICAL] Mirai Variant MooBot Targeting D-Link Devices
Threat Research Center
Threat Research
Vulnerabilities
## Mirai Variant MooBot Targeting D-Link Devices
Chao Lei
Zhibin Zhang
Cecilia Hu
Aveek Das
Published: September 6, 2022
Malware
Threat Research
Vulnerabilities
CVE-2015-2051
CVE-2018-6530
CVE-2022-26258
CVE-2022-28958
IoT
Mirai
MooBot
SOHO
## Executive Summary
In early August, Unit 42 researchers discovered attacks leveraging several vulnerabilities in devices made by D-Link, a company that specializes in network and connectivity products. The vulnerabilities exploited include:
CVE-2015-2051 : D-Link HNAP SOAPAction Header Command Execution Vulnerability
CVE-2018-6530 : D-Link SOAP Interface Remote Code Execution Vulnerability
CVE-2022-26258 : D-Link Remote Command Execution Vulnerability
CVE-2022-28958 :
https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.mdhttps://www.dlink.com/en/security-bulletin/https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.mdhttps://www.dlink.com/en/security-bulletin/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26258
2022-03-28
Published
2022-09-08
Added to CISA KEV
Exploited in the wild