ZeroHour

CVE-2021-45382

KEV PoC large

Command Injection RCE in D-Link DIR-810L/820L/826L/830L/836L Routers

CISA: D-Link Multiple Routers Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

A command injection flaw (CWE-78) in the Dynamic DNS (DDNS) handling of the ncc2 binary allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers. Because the DDNS function passes attacker-controlled input to a system shell without sanitization, a crafted request to the router's web service triggers command execution with the device's privileges (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). A successful attacker gains full control of the router, enabling botnet enrollment, traffic interception, or pivoting into the local network. All hardware revisions of these five consumer/SOHO routers are affected, and because every model has reached End of Life/End of Service Life, D-Link will not issue patches. The flaw carries a 97.8% EPSS score, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-04, and has a public proof-of-concept, indicating active in-the-wild exploitation.

What to do: Replace or retire any in-use DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, or DIR-836L router, as no firmware patch will be released. If replacement must wait, disable the DDNS feature and WAN-facing remote management, and verify the admin interface is not reachable from the internet. CISA's required action is to disconnect these end-of-life devices if they are still in service.

Affected
D-Link DIR-810L firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
D-Link DIR-820L firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
D-Link DIR-820LW firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
D-Link DIR-826L firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
D-Link DIR-830L firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
D-Link DIR-836L firmwareall hardware revisions, all firmware versions (EOL/EOS, no patch)
Estimated exposure
largetens of thousands of internet-exposed units; combined installed base of the five EOL models plausibly in the hundreds of thousands — Estimated from these models' multi-year run as mainstream D-Link consumer/SOHO routers sold globally and typical counts of exposed D-Link DIR-series web interfaces in public internet scans; no vendor sales telemetry is provided in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.

CISA Known Exploited Vulnerability
Affected
D-Link Multiple Routers
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-820l firmware, dir-820lw firmware, dir-826l firmware, dir-830l firmware, dir-836l firmware, dir-810l firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news