CVE-2026-7067
published 2026-04-27CVE-2026-7067: A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP…
PriorityP358high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
2.48%
82.7th percentile
A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-822 | — | — |
| dlink | dir-822_firmware | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DIR-822 A_101 udhcpd DHCP Service /udhcpcd/dhcpd.c system Hostname command injection (EUVD-2026-25737 / CNNVD-202604-5313)
vuldb·2026-04-29·CVSS 6.9
CVE-2026-7067 [MEDIUM] D-Link DIR-822 A_101 udhcpd DHCP Service /udhcpcd/dhcpd.c system Hostname command injection (EUVD-2026-25737 / CNNVD-202604-5313)
A vulnerability identified as critical has been detected in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-7067. The attack can be initiated remotely. Additionally, an exploit exists.
GHSA
GHSA-5qjf-gvp4-pqxh: A vulnerability was determined in D-Link DIR-822 A_101
ghsa_unreviewed·2026-04-27
CVE-2026-7067 [MEDIUM] CWE-74 GHSA-5qjf-gvp4-pqxh: A vulnerability was determined in D-Link DIR-822 A_101
A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
No detection rules found.
No public exploits indexed.
2026-04-27
Published