Overview
- Description
- A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Known exploits
Data from CISA
- Vulnerability name
- D-Link Multiple Routers Remote Code Execution Vulnerability
- Exploit added on
- Apr 4, 2022
- Exploit action due
- Apr 25, 2022
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
Weaknesses
- nvd@nist.gov
- CWE-78
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-820l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "88CE60CD-DCDA-43E0-80A9-257557EDBC29" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-820l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC65DE67-1143-4165-BCE2-1EBEB2510003" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-820lw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9CFE3EE8-70B8-4A1D-A449-A31B3E4897AB" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-820lw_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5D0B0B3-29C1-4143-B1C2-D228AA9694B8" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-826l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36554D63-D4A3-499A-BD79-8C8729CB003E" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-826l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B65A1C2-670D-49A3-91D4-B592815CC6D7" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-830l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "889685BB-EFD4-46CA-BBF1-F215DAD02C92" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-830l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E09C68C8-3CCF-43A9-AE31-011F08A93F55" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-836l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EE2ED91B-738D-448B-B7E0-D869539571F1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-836l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D284E3D-970D-41A7-B7CA-B531D2BE5666" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:dlink:dir-810l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8B79563C-609A-4F9F-8F2F-FFF3D10E6684" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:dlink:dir-810l_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C56CE73-9B68-4A0A-A2A3-878D90A0D4EF" } ], "operator": "OR" } ], "operator": "AND" } ]