CISA adds 12 new flaws to Known Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2011-4723 | Cleartext Password Storage in D-Link DIR-300 Router D-Link DIR-300 routers store passwords in cleartext rather than hashed or encrypted form (CWE-310), meaning credentials configured on the device remain readable as plaintext in its stored configuration. Triggering the flaw is context-dependent: an attacker who can obtain the router's stored configuration, for example through its management interface, a configuration backup, or direct access to the device, can read the passwords in plaintext. The attacker gains access to sensitive credentials, typically the router's administration and/or wireless passwords, which can be used to take over the device or to compromise other systems where the same passwords were reused. Only the D-Link DIR-300 is listed as affected by CISA; the model is end-of-life, so any owner still running it is exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming active exploitation in the wild (ransomware use unknown), and EPSS currently estimates a 3% probability of exploitation activity in the next 30 days (86th percentile). Do: Because the DIR-300 is end-of-life, CISA's required action is to disconnect it if still in use; replace it with a supported router rather than expecting further firmware fixes. If replacement must be delayed, restrict management access to trusted clients, do not expose the device's web interface to the internet, and rotate any passwords configured on the device, especially ones reused elsewhere, since they are recoverable in cleartext. Audit networks for remaining DIR-300 units, particularly in internet-facing positions. | — | 3% | KEV |
| large≈ hundreds of thousands of DIR-300 units still in use worldwide (order-of-magnitude estimate) | |
| CVE-2018-6530 | Unauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile). Do: Apply the latest available firmware from D-Link — the vendor advisory states that the fix released under CVE-2018-20114 properly patches this vulnerability. Because all four affected models have reached end-of-life, CISA recommends disconnecting any affected device still in use if no supported firmware is available, and replacing it if it is internet-facing. As an interim mitigation, block or restrict WAN access to the router's web/SOAP (soap.cgi/HNAP) interface and check device logs for unexpected outbound connections indicative of MooBot/Mirai compromise. | 9.8 | 97% | KEV ransomware PoC |
| massorder of 100,000+ internet-exposed devices, with total installed units across the four consumer router models plausibly in the millions (estimate) | |
| CVE-2022-26258 | Unauthenticated Remote Command Execution in D-Link DIR-820L Router CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices. Do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy. | 9.8 | 92% | KEV PoC ×2 |
| large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router) | |
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Flaw Exploited by DeadBolt Ransomware CVE-2022-27593 is a critical (CVSS 9.1) externally controlled reference to a resource (CWE-610, an SSRF-style flaw) in the Photo Station photo-sharing application for QNAP NAS devices running QTS. Because the flaw is reachable over the network with no privileges or user interaction required, an unauthenticated attacker who can reach a Photo Station instance can force the application to reference attacker-controlled resources and modify system files. This is the vulnerability the DeadBolt ransomware operation exploited to compromise and encrypt thousands of internet-facing QNAP NAS devices in 2022. Any QNAP NAS running vulnerable Photo Station versions across QTS 4.2.x through 5.x is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08, ransomware use is known, and EPSS puts the 30-day exploitation probability at 87.9% (100th percentile), though no public PoC is known. Do: Upgrade Photo Station to the fixed version for your QTS branch: 6.1.2+ on QTS 5.0.1, 6.0.22+ on QTS 5.0.0/4.5.x, 5.7.18+ on QTS 4.3.6, 5.4.15+ on QTS 4.3.3, and 5.2.14+ on QTS 4.2.6. If patching is not immediately possible, disable Photo Station or remove it from internet exposure, since the flaw requires no authentication. Check devices for DeadBolt compromise (encrypted files and ransom notes) and apply updates per CISA's KEV required action and QNAP's instructions. | 9.1 | 88% | KEV ransomware |
| large≈ tens of thousands of internet-exposed QNAP NAS devices running Photo Station, with thousands confirmed encrypted by DeadBolt | |
| CVE-2022-28958 | Rejected reason: DO NOT USE THIS CVE RECORD. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. NVD description · AI analysis pending | — | — | — | — | ||
| CVE-2022-3075 | Actively Exploited Sandbox Escape via Insufficient Mojo Validation in Google Chrome CVE-2022-3075 is an insufficient data validation flaw (CWE-20) in Mojo, the inter-process communication layer of the Chromium browser engine, affecting Google Chrome versions prior to 105.0.5195.102. An attacker triggers it via a crafted HTML page after first compromising the browser's renderer process; the bug then allows code to escape the Chrome sandbox. Successful exploitation yields execution outside the renderer sandbox, potentially giving the attacker broader access to the host, which the 9.6 CVSS score reflects via network attack vector, user interaction, and high impact across the changed scope. All users of Google Chrome prior to 105.0.5195.102 are exposed, and Fedora, which ships Chromium-based browser packages, is also listed as affected. The flaw was confirmed as a zero-day exploited in the wild — Google's ninth actively exploited Chrome zero-day of 2022 — was added to CISA's KEV catalog on 2022-09-08, and carries a 5.8% EPSS probability of exploitation within 30 days. Do: Update Google Chrome to 105.0.5195.102 or later on all desktop platforms and restart the browser; verify the running version via chrome://version. Fedora users should immediately apply system updates to receive rebuilt Chromium packages. Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, KEV-bound organizations (including federal agencies) must apply the vendor updates by the required deadline. | 9.6 | 6% | KEV |
| mass≈3 billion+ users (order of magnitude: billions, based on Chrome's dominant market share) |
Full article273 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 08, 2022

CISA added 12 more security flaws to its Known Exploited Vulnerabilities Catalog including four D-Link vulnerabilities.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added 12 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including four vulnerabilities in D-Link routers, two Chrome zero-day issues, and a recently disclosed flaw in the QNAP Photo Station.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
Below is the list of the flaws added to the catalog:
The vulnerabilities in D-Link routers added to the catalog are:
- CVE-2022-28958 D-Link DIR-816L Remote Code Execution Vulnerability
- CVE-2022-26258 D-Link DIR-820L Remote Code Execution Vulnerability
- CVE-2018-6530 D-Link Multiple Routers OS Command Injection Vulnerability
- CVE-2011-4723 D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
Last week, Google rolled out emergency fixes to address a vulnerability, tracked as CVE-2022-3075, in the Chrome web browser that is being actively exploited in the wild. Now CISA added this flaw to the Catalog.
CISA also added the CVE-2022-27593 in QNAP NAS appliances to its catalog. This week, the Taiwanese vendor warned its customers of ongoing DeadBolt ransomware attacks that are exploiting a zero-day vulnerability in Photo Station.
CISA orders federal agencies to fix these vulnerabilities by September 29, 2022.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, CISA)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/135491/security/cisa-known-exploited-vulnerabilities-catalog-flaws-2.html