PT-2022-1646 · D Link · D-Link Dir-830L+4

Huanbin Ruan

·

Published

2022-02-17

·

Updated

2025-11-10

·

CVE-2021-45382

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-link DIR-810L versions all D-link DIR-820L/LW versions all D-link DIR-826L versions all D-link DIR-830L versions all D-link DIR-836L versions all
Description A Remote Command Execution vulnerability exists in the DDNS function of the affected routers, allowing a remote attacker to execute arbitrary commands. The issue is related to insufficient checking of arguments passed to a command. The affected routers have reached their End of Life (EOL) / End of Service Life (EOS) Life-Cycle, and as such, this issue will not be patched.
Recommendations For D-link DIR-810L, consider disabling the DDNS function to minimize the risk of exploitation. For D-link DIR-820L/LW, consider disabling the DDNS function to minimize the risk of exploitation. For D-link DIR-826L, consider disabling the DDNS function to minimize the risk of exploitation. For D-link DIR-830L, consider disabling the DDNS function to minimize the risk of exploitation. For D-link DIR-836L, consider disabling the DDNS function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-00895
CVE-2021-45382

Affected Products

D-Link Dir-810L
D-Link Dir-820L/Lw
D-Link Dir-826L
D-Link Dir-830L
D-Link Dir-836L