Showing posts with label KEV Catalog. Show all posts
Showing posts with label KEV Catalog. Show all posts

Friday, April 24, 2026

CISA Adds D-Link DIR-823X Vulnerability to KEV Catalog – 4-24-26

 Today CISA announced that it had added command injection vulnerability (CVE-2025-29635) in the D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router. The vulnerability was originally reported (with proof-of-concept code) by Wang Jinshuai and Zhao Jiangting at https://github.com/mono7s/, but that report was subsequently removed. D-Link responded in September 2025, noting that the router was end-of-life and no fix was planned. 

Earlier this month Akamai reported that they had seen CVE-2025-29635 being exploited itheir honey pots to deploy the Mirai botnet 

CISA has directed federal agencies using the wireless router to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. A deadline of May 8th2026 has been established. Since the product is end-of-life and no fix is available, agencies would be required to stop using the D-Link DIR-823X routers. 

Wednesday, August 21, 2024

CISA Adds 2 IP Camera Vulnerabilities to KEV Catalog – 8-21-24

Today, CISA announced that it had added four vulnerabilities to their Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities included two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) for 19 different Dahua Security IP cameras. The vulnerabilities were publicly disclosed (with proof-of-concept code) by bashis on October 6th, 2021. That disclosure was a coordinated disclosure with Dahau reportedly having a new firmware version available that mitigated the two vulnerabilities.

CISA noted in their announcement that:

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.”

Thursday, April 11, 2024

CISA Adds 2 NAS Vulnerabilities to KEV Catalog

Today, CISA added two new vulnerabilities to their Known Exploited Vulnerabilities Catalog, both for multiple NAS devices from D-Link. The two vulnerabilities are:

• Use of hard-coded credentials - CVE-2024-3272, and

• Command injection - CVE-2024-3273

NOTE: Both of the links above apply to both vulnerabilities.

While not included in the KEV addition notice, the CVE record for -3273 includes the following in the KEV notice for the CVE:

“This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.”

On an odd note (and a brief commentary on the continuing NVD.NIST.gov problems) only the -3273 CVE entry notes that the CVE has been listed in the KEV Catalog. The -3272 entry currently (2113 EDT, 4-11-24) does not mention that the CVE has been so listed.

 
/* Use this with templates/template-twocol.html */