CVE-2021-45382
KEV PoC largeCommand Injection RCE in D-Link DIR-810L/820L/826L/830L/836L Routers
CISA: D-Link Multiple Routers Remote Code Execution Vulnerability
A command injection flaw (CWE-78) in the Dynamic DNS (DDNS) handling of the ncc2 binary allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers. Because the DDNS function passes attacker-controlled input to a system shell without sanitization, a crafted request to the router's web service triggers command execution with the device's privileges (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). A successful attacker gains full control of the router, enabling botnet enrollment, traffic interception, or pivoting into the local network. All hardware revisions of these five consumer/SOHO routers are affected, and because every model has reached End of Life/End of Service Life, D-Link will not issue patches. The flaw carries a 97.8% EPSS score, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-04, and has a public proof-of-concept, indicating active in-the-wild exploitation.
What to do: Replace or retire any in-use DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, or DIR-836L router, as no firmware patch will be released. If replacement must wait, disable the DDNS feature and WAN-facing remote management, and verify the admin interface is not reachable from the internet. CISA's required action is to disconnect these end-of-life devices if they are still in service.
| D-Link DIR-810L firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
| D-Link DIR-820L firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
| D-Link DIR-820LW firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
| D-Link DIR-826L firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
| D-Link DIR-830L firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
| D-Link DIR-836L firmware | all hardware revisions, all firmware versions (EOL/EOS, no patch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
- Affected
- D-Link Multiple Routers
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dir-820l firmware, dir-820lw firmware, dir-826l firmware, dir-830l firmware, dir-836l firmware, dir-810l firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H