CVE-2026-7067Disclosure(dlink / dir-822)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch dlink dir-822 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-822
  • dir-822_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-27); latest day: 3
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
dir-822dir-822_firmware

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-04-27: 4Mentions · 2026-04-30: 1Mentions · 2026-05-23: 3Active Exploitation · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-30: 1Technical Details · 2026-05-23: 304-2704-3005-23
Signal classification4 categories
Disclosure
562.5%
Active Exploitation
112.5%
General
112.5%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-274
Active Exploitation1Disclosure2General1
2026-04-301
Patch1
2026-05-233
Disclosure3
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    D-Link DIR-822 DHCP Command Injection: Legacy Router Becomes RCE Hotspot (CVE-2026-7067) D-Link DIR-822 A101 routers contain a command injection vulnerability in the udhcpd DHCP service component.

    Post summary

    A command injection flaw in the udhcpd DHCP service of D‑Link DIR‑822 A101 routers can enable remote code execution.

    1000045
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    D-Link DIR-822 DHCP Command Injection: Another Legacy Router Becomes an RCE Hotspot (CVE-2026-7067). D-Link DIR-822 A101 routers contain a command injection vulnerability in the udhcpd DHCP service component.

    Post summary

    D-Link DIR‑822 A101 routers contain a command‑injection flaw in the udhcpd DHCP service that could lead to remote code execution; the statement is an announcement of the vulnerability with no PoC, exploit tool, or patch details reported.

    1000055
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CVE-2026-7067, disclosed today, exposes D-Link DIR-822 A101 routers to unauthenticated remote command injection via DHCP hostname arguments. CVSS 7.3. Exploit publicly available. No patches coming—the product is end-of-life.

    Post summary

    The post announces CVE‑2026‑7067, a remote command‑injection flaw in D‑Link DIR‑822 A101 routers, highlighting its CVSS score, lack of patches due to EOL, and the existence of a publicly available exploit.

    1000053
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7067 A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. T… https://www.cve.org/CVERecord?id=CVE-2026-7067

    Post summary

    A CVE was disclosed for a vulnerability in the D-Link DIR-822 DIR-822 A_101 router, affecting the udhcpd DHCP Service via the function system in the file /udhcpcd/dhcpd.c.

    00010130
    57.3K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-7067 (CVSS 7.3) - D-Link DIR-822 A_101 command injection via DHCP Hostname parameter. Exploit public. Affects EOL products only. Patch unavailable - replace device. #CVE #PatchNow https://t.co/92mCfkPbVA

    Post summary

    The tweet announces a command‑injection CVE in D‑Link DIR‑822, notes that no patch is available for end‑of‑life devices and recommends replacement, but it provides no exploit code or evidence of current exploitation.

    0000020
    11 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    D-Link DIR-822 CVE-2026-7067 is under active exploitation—attackers can inject system commands via the DHCP service, risking full control. Patch now to prevent potential breaches. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #DataBreach https://t.co/PvwM04zTvK

    Post summary

    CVE-2026-7067 on D‑Link DIR‑822 is actively exploited; attackers can inject system commands via the DHCP service, and administrators are urged to apply a patch immediately.

    0000036
    57 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7067 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7067 #CVE-2026-7067 #CVE #High #CyberSecurity #InfoSec https://t.co/2MhcH39q9b

    Post summary

    The tweet reports the existence of CVE-2026-7067 with a severity of 7.3 but provides no further technical, exploit, or patch information.

    0000049
    141 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7067 Command Injection in D-Link DIR-822 A_101 udhcpd DHCP Service via Hostname https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7067

    Post summary

    A brief disclosure of a command injection vulnerability in D-Link DIR‑822 A_101 uDHCPD via the hostname field, but lacking any PoC, patch, or exploitation details.

    0000054
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-822a1--
OSdlinkdir-822_firmware1.0.1--

Explore more