Remote Code Execution Vulnerabilities in D-Link Devices
Article Content
- •CVE-2022-26258 and CVE-2019-16057 are critical vulnerabilities in D-Link devices.
- •Both vulnerabilities allow remote code execution with a CVSS score of 9.8.
- •CISA confirmed active exploitation and remediation deadlines have passed.
Two vulnerabilities have been identified in D-Link devices, CVE-2022-26258 and CVE-2019-16057, both allowing remote code execution. CVE-2022-26258 affects the D-Link DIR-820L router, while CVE-2019-16057 impacts the D-Link DNS-320 storage device. Both vulnerabilities have a CVSS score of 9.8, categorizing them as. CISA confirmed exploitation in the wild for both vulnerabilities, with CVE-2022-26258 added to the KEV catalog on September 8, 2022, and CVE-2019-16057 on April 15, 2022. The CISA remediation deadlines for both vulnerabilities have long passed, raising concerns about devices. Affected organizations include US federal civilian agencies and other users of these D-Link products. The vulnerabilities stem from issues in the device's web management interfaces, allowing attackers to execute arbitrary code remotely. Users are urged to apply patches and secure their devices against potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2019-16057 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which D-Link devices are affected?
What is the CVSS score for these vulnerabilities?
What actions should be taken to mitigate these vulnerabilities?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…