S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-45382 Scanner

CVE-2021-45382 scanner - Remote Command Execution vulnerability in D-Link routers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-45382
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

D-Link routers, including models DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L, are widely used networking devices that provide users with internet access and network connectivity. These routers are designed for both home and small office environments, offering features such as dual-band Wi-Fi, cloud services, and advanced security protocols. They are popular due to their ease of use, reliability, and performance. However, the identified models have reached their End of Life (EOL)/End of Service Life (EOS), meaning they are no longer supported by the manufacturer.

Attackers can exploit this vulnerability by sending a specially crafted POST request to the /ddns_check.ccp endpoint. The request includes a malicious DDNS hostname parameter that injects commands to be executed by the router. Since these routers are no longer supported, they do not receive security updates, making them permanently vulnerable to such attacks.

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, device manipulation, or being co-opted into botnets. Attackers can potentially redirect traffic, monitor or alter network communications, and launch further attacks against connected devices. The high CVSS score reflects the severity and potential impact of this vulnerability on affected users.

By utilizing the security scanning services provided by S4E, users can identify vulnerabilities such as the critical RCE flaw in D-Link routers. Our platform's comprehensive approach to cyber threat exposure management helps organizations detect, analyze, and remediate vulnerabilities before they can be exploited. Joining S4E ensures continuous protection and enhances cybersecurity resilience against evolving threats.

 

References

Solution Advice
  1. Users with affected router models should consider replacing them with newer, supported devices.
  2. Disconnect or replace EOL/EOS devices from your network to prevent potential exploitation.
  3. Apply strict network segmentation and firewall rules to minimize the exposure of vulnerable devices.
  4. Regularly monitor network traffic for unusual activities that may indicate exploitation attempts.
  5. Educate users and administrators about the risks associated with using unsupported devices and the importance of timely hardware updates.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.