A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 810l
HWDlinkall versionsDlink Dir 810l Firmware
OSDlinkall versionsDlink Dir 820l
HWDlinkall versionsDlink Dir 820l Firmware
OSDlinkall versionsDlink Dir 820lw
HWDlinkall versionsDlink Dir 820lw Firmware
OSDlinkall versionsDlink Dir 826l
HWDlinkall versionsDlink Dir 826l Firmware
OSDlinkall versionsDlink Dir 830l
HWDlinkall versionsDlink Dir 830l Firmware
OSDlinkall versionsDlink Dir 836l
HWDlinkall versionsDlink Dir 836l Firmware
OSDlinkall versions
CISA KEV — detailsi
- Vendori
- D-Link
- Producti
- Multiple Routers
- Added to KEVi
- April 4, 2022
- Remediation deadline (US Federal)i
- April 25, 2022(overdue)
The impacted product is end-of-life and should be disconnected if still in use.
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
Related vulnerabilities
Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root
RCE w D-Link DIR-820L — command injection przez HTTP POST
Command Injection w narzędziu ping urządzeń D-Link i TRENDnet — RCE bez uwierzytelnienia
D-Link DIR-820L: stack overflow w funkcji sub_451208
D-Link DIR-820LW – zakodowane na stałe dane logowania w usłudze Telnet