CVE-2022-40799
KEV PoC moderateUnsigned Code Download Enables OS Command Execution in D-Link DNR-322L NVR
CISA: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
CVE-2022-40799 is a download-of-code-without-integrity-check flaw (CWE-494) in the D-Link DNR-322L network video recorder, which accepts and runs downloaded code without verifying it is authentic and unmodified. An attacker who already holds valid credentials on the device can trigger download and execution of unsigned code, gaining the ability to issue operating-system-level commands on the NVR. Successful exploitation yields control of the recorder, its stored camera footage, and a foothold for further attacks on the surveillance network. Only D-Link DNR-322L deployments are affected, and the product is end-of-life/end-of-service, so owners should expect limited or no vendor remediation and are advised to discontinue use. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2025-08-05, EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), and no public proof-of-concept is known.
What to do: Inventory your environment for DNR-322L recorders and, per CISA's required action, apply any mitigations D-Link has published or retire the device, since the product is EoL/EoS and the vendor recommends discontinuing use. If the recorder must stay in service, keep its management interface off the public internet behind a firewall and monitor for signs of command execution; federal agencies must remediate or discontinue use in line with BOD 22-01 deadlines.
| D-Link DNR-322L Network Video Recorder | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.
- Affected
- D-Link DNR-322L
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dnr-322l firmware
- Weakness
- CWE-494
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H