{"id":"CVE-2022-26258","title":"D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.","summary":"D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78","CWE-78"],"vendor":"dlink","product":"dir-820l_firmware","affected":["dir-820l_firmware = 1.05b03"],"published":"2022-03-28","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-26258","references":[{"url":"https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0","label":"cve@mitre.org"},{"url":"https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.md","label":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","label":"cve@mitre.org"},{"url":"http://dir-820l.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://dlink.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.md","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.dlink.com/en/security-bulletin/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26258","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.91981,"epssPercentile":0.99818,"kev":true,"kevDateAdded":"2022-09-08","kevDueDate":"2022-09-29","kevRansomware":false,"exploited":true,"ingestedAt":"2026-07-06T02:09:23.448Z","slug":"CVE-2022-26258","body":"## Overview\n\nD-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.\n\n## Affected\n\n- `dir-820l_firmware = 1.05b03`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":97,"depthScoreParts":{"impact":53.9,"likelihood":18.4,"exploitation":25,"ransomware":0},"changes":[{"seq":228,"id":"CVE-2022-26258","ts":1788815932354,"field":"epss","old":"0.80377","new":"0.91981"}]}