← Back to browse · API

CVE-2022-36786

Severity
CRITICAL
CVSS
9.9
EPSS
0.00856
Risk score
39.9
CISA KEV
No
PoC
No
Published
2022-11-17
Modified
2025-04-29
First seen
2026-08-07
Aliases
EUVD-2022-39486, GHSA-6X6F-2749-HHGV
Products
D-Link:DSL-224 All versions <Update to version 3.0.9_Beta Hotfix
Sources
euvd EUVD-2022-39486

Description

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

References