LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-45382: D-Link Multiple Routers Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 4, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 25, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-45382 to its Known Exploited Vulnerabilities catalog on Apr 4, 2022, with a federal patch deadline of Apr 25, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

CVE-2021-45382 is a remote code execution vulnerability affecting multiple D-Link routers. It involves the DDNS function in the ncc2 binary and can allow an attacker to run commands on the device. Because these products are end-of-life, the practical risk is high for any still-connected units: a compromised router can expose the internal network, intercept traffic, or serve as a foothold for further intrusion. Confirm all product and revision details against the vendor advisory and CISA guidance.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In this class of flaw, input that reaches a system command is not properly sanitized, so an attacker can inject additional commands that the device executes with the privileges of the vulnerable process.

According to the CISA summary, the issue exists via the DDNS function in the ncc2 binary across all series hardware revisions of the affected routers. An attacker who can reach that function—typically over the network—can abuse it to achieve remote code execution. Exact request format, authentication requirements, and exploit mechanics are not detailed here; treat any internet-facing or poorly segmented management/DDNS interface as potentially reachable and verify behavior only against the official advisory.

Am I affected? How to find it in your systems

D-Link consumer and small-office routers commonly sit at the network edge as the default gateway, providing WAN, Wi-Fi, and sometimes VPN or DDNS services. Inventory every D-Link device still in production or lab use.

Because the products are end-of-life, assume no further security fixes will be issued and treat any remaining unit as high priority for removal.

How to remediate

CISA’s required action is clear: the impacted product is end-of-life and should be disconnected if still in use. Replacement with a supported router is the primary remediation.

If you can't patch immediately

When immediate replacement is impossible, reduce exposure until the device can be removed.

If your data may have been exposed

Actively exploited edge vulnerabilities frequently lead to network compromise and data exposure. If these routers were internet-facing or showed signs of intrusion, assume credentials, traffic, or internal hosts may have been at risk; rotate passwords, review connected systems, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · Multiple Routers
WeaknessCWE-78
Added to CISA KEVApr 4, 2022
Federal patch deadlineApr 25, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities