First published: Thu Feb 17 2022(Updated: )
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-820l Firmware | ||
Dlink Dir-820l | ||
Dlink Dir-820lw Firmware | ||
Dlink Dir-820lw | ||
Dlink Dir-826l Firmware | ||
Dlink Dir-826l | ||
Dlink Dir-830l Firmware | ||
Dlink Dir-830l | ||
Dlink Dir-836l Firmware | ||
Dlink Dir-836l | ||
Dlink Dir-810l Firmware | ||
Dlink Dir-810l | ||
D-Link Multiple Routers | ||
All of | ||
Dlink Dir-820l | ||
Dlink Dir-820l Firmware | ||
All of | ||
Dlink Dir-820lw | ||
Dlink Dir-820lw Firmware | ||
All of | ||
Dlink Dir-826l | ||
Dlink Dir-826l Firmware | ||
All of | ||
Dlink Dir-830l | ||
Dlink Dir-830l Firmware | ||
All of | ||
Dlink Dir-836l | ||
Dlink Dir-836l Firmware | ||
All of | ||
Dlink Dir-810l | ||
Dlink Dir-810l Firmware |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45382 is a Remote Code Execution (RCE) vulnerability in multiple D-Link routers.
The following D-Link routers are affected by CVE-2021-45382: DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L.
CVE-2021-45382 has a severity rating of 9.8 (Critical).
CVE-2021-45382 allows remote attackers to execute arbitrary code on the affected D-Link routers through the DDNS function in the ncc2 binary file.
To fix CVE-2021-45382, it is recommended to update the firmware of the affected D-Link routers to the latest version provided by D-Link.