{"cveID":"CVE-2021-45382","vendorProject":"D-Link","product":"Multiple Routers","vulnerabilityName":"D-Link Multiple Routers Remote Code Execution Vulnerability","dateAdded":"2022-04-04","shortDescription":"A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.","requiredAction":"The impacted product is end-of-life and should be disconnected if still in use.","dueDate":"2022-04-25","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-45382","cwes":["CWE-78"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1070","technique_name_at_mapping":"Indicator Removal","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1071","technique_name_at_mapping":"Application Layer Protocol","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1499.002","technique_name_at_mapping":"Service Exhaustion Flood","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-45382","technique":"T1543","technique_name_at_mapping":"Create or Modify System Process","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This remote command execution vulnerability is exploited by an unauthenticated, remote adversary via the DDNS function in ncc2 binary file. Adversaries have leveraged this vulnerability to spread a variant of Mirai botnet called Beastmode and  IZ1H9 to cause a distributed denial of service attack. \n\nIn the IZ1H9 attack, once the attackers took advantage of the vulnerability, they injected the IZ1H9 payload into the device. This program included instructions to download another script from a specific web address. When this script ran, it erased records to cover up the malicious actions and then downloaded additional software designed for different types of devices. The script also changed the device's settings to block certain network connections, making it more difficult to remove the malware. After these steps, the infected device connected to a control server, waiting for instructions on which type of denial-of-service attack to carry out, such as disrupting services using various internet protocols.\n\nIn the Beastmode attack, exploiting the vulnerability led to the download and execution of a script called \"ddns.sh.\" This script then fetched the Beastmode program, which was saved and run with specific settings. These settings allowed the infected device to join a subgroup within the larger botnet, helping the attackers manage and assess the effectiveness of their exploits. Once devices were compromised by Beastmode, the botnet could be used to launch various types of denial-of-service attacks, similar to those seen in other Mirai-based botnets.","references":["https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign","https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/","https://www.malwarebytes.com/blog/news/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline","https://thehackernews.com/2022/04/beastmode-ddos-botnet-exploiting-new.html","https://www.bleepingcomputer.com/news/security/mirai-ddos-malware-variant-expands-targets-with-13-router-exploits/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1070","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Indicator Removal","name_at_mapping":"Indicator Removal","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1071","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Application Layer Protocol","name_at_mapping":"Application Layer Protocol","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":7,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1499.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Service Exhaustion Flood","name_at_mapping":"Service Exhaustion Flood","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true},{"id":"T1543","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Create or Modify System Process","name_at_mapping":"Create or Modify System Process","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":9,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}