{"cveID":"CVE-2022-26258","vendorProject":"D-Link","product":"DIR-820L","vulnerabilityName":"D-Link DIR-820L Remote Code Execution Vulnerability","dateAdded":"2022-09-08","shortDescription":"D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.","requiredAction":"The impacted product is end-of-life and should be disconnected if still in use.","dueDate":"2022-09-29","knownRansomwareCampaignUse":"Unknown","notes":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10295;  https://nvd.nist.gov/vuln/detail/CVE-2022-26258","cwes":["CWE-78"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-26258","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an adversary via HTTP POST to get set ccp. The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called MooBot to cause a distributed denial of service attack. ","references":["https://thehackernews.com/2022/09/mirai-variant-moobot-botnet-exploiting.html","https://unit42.paloaltonetworks.com/moobot-d-link-devices/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26258","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an adversary via HTTP POST to get set ccp. The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called MooBot to cause a distributed denial of service attack. ","references":["https://thehackernews.com/2022/09/mirai-variant-moobot-botnet-exploiting.html","https://unit42.paloaltonetworks.com/moobot-d-link-devices/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26258","technique":"T1499.002","technique_name_at_mapping":"Service Exhaustion Flood","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an adversary via HTTP POST to get set ccp. The exploit targets a command injection vulnerability in the /lan.asp component. The component does not successfully sanitize the value of the HTTP parameter DeviceName, which in turn can lead to arbitrary command execution. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called MooBot to cause a distributed denial of service attack. ","references":["https://thehackernews.com/2022/09/mirai-variant-moobot-botnet-exploiting.html","https://unit42.paloaltonetworks.com/moobot-d-link-devices/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1499.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Service Exhaustion Flood","name_at_mapping":"Service Exhaustion Flood","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}