DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API.
It is possible to inject a command through this interface that will run with ROOT permissions on the router.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 3.0.9_Beta Hotfix
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39486 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. |
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 29 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2025-04-29T20:01:06.332Z
Reserved: 2022-07-26T00:00:00.000Z
Link: CVE-2022-36786
Updated: 2024-08-03T10:14:28.406Z
Status : Modified
Published: 2022-11-17T23:15:17.010
Modified: 2025-04-29T20:15:20.280
Link: CVE-2022-36786
No data.
OpenCVE Enrichment
No data.
EUVD