Description
DLINK - DSL-224 Post-auth RCE.
DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API.
It is possible to inject a command through this interface that will run with ROOT permissions on the router.
DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API.
It is possible to inject a command through this interface that will run with ROOT permissions on the router.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.0.9_Beta Hotfix
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39486 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 29 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2025-04-29T20:01:06.332Z
Reserved: 2022-07-26T00:00:00.000Z
Link: CVE-2022-36786
Updated: 2024-08-03T10:14:28.406Z
Status : Modified
Published: 2022-11-17T23:15:17.010
Modified: 2025-04-29T20:15:20.280
Link: CVE-2022-36786
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD