Executive brief
A remote command execution vulnerability exists in multiple D-Link router models via the DDNS function in the ncc2 binary file. The flaw allows an unauthenticated attacker to execute arbitrary commands over the network. Affected devices have reached End of Life (EOL) and will not receive security patches.
Affected products
- D-Link DIR-810L All hardware revisions; End of Life
- D-Link DIR-820L/LW All hardware revisions; End of Life
- D-Link DIR-826L All hardware revisions; End of Life
- D-Link DIR-830L All hardware revisions; End of Life
- D-Link DIR-836L All hardware revisions; End of Life
Timeline
- 2022-02-17: disclosed: NVD Published Date
- 2022-04-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-04: advisory: Publication date of the advisory provided.