Skip to content
COOEY

EXPOSURES › CVE-2021-45382

CVE-2021-45382

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-45382 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

D-Link routers shipped with a remote code execution flaw in the DDNS function that was actively exploited in the wild.

D-Link routers contained an RCE vulnerability in the ncc2 binary via the DDNS function, allowing attackers to execute arbitrary code remotely. This is a critical failure for DIB organizations because it enables lateral movement and data exfiltration, directly impacting CMMC/NIST 800-171 compliance by violating system integrity and access control requirements. Organizations must ensure all network hardware is patched and monitored for known KEV vulnerabilities.

Shame score — D-Link repeatedly shipped consumer-grade firmware with critical RCE flaws that were actively exploited in the wild, demonstrating a pattern of negligence and avoidable risk to the supply chain.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.