Cyber Security News

Multiple D-Link End-of-Life Routers Vulnerabilities Let Attackers Execute Remote Code

D-Link, a prominent networking hardware manufacturer, has issued a critical security advisory urging users to retire and replace several end-of-life VPN router models due to a severe remote code execution (RCE) vulnerability.

The affected devices include all hardware revisions of DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, and DSR-1000N routers.

The vulnerability, discovered by security researcher ‘delsploit,’ allows unauthenticated users to execute remote code on the affected devices due to a stack buffer overflow issue.

D-Link has not assigned a CVE identifier to this flaw, likely to prevent widespread exploitation attempts.

Most of the impacted models reached their end-of-service life on May 1, 2024, with the DSR-500N and DSR-1000N having been discontinued in 2015.

Affected models (Source – D-Link)

D-Link has made it clear that they will not be releasing security updates for these devices, as their general policy is to cease all firmware development and support for products that have reached end-of-life status.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

The company strongly advises users to retire these routers immediately, warning that continued use may pose significant risks to connected devices.

For those who choose to keep using the affected routers against D-Link’s recommendations, the company suggests ensuring that the latest available firmware is installed, frequently updating the device’s unique password, and always enabling Wi-Fi encryption with a separate password.

To assist affected customers in the United States, D-Link is offering a 20% discount on the purchase of a newer model, the DSR-250v2 4-Port Unified Services VPN Router.

However, this offer does little to address the security concerns of users who may be unable or unwilling to upgrade immediately.

This incident follows a recent pattern of D-Link declining to patch critical vulnerabilities in end-of-life devices.

Earlier this month, the company faced criticism for not addressing a severe flaw affecting thousands of end-of-life NAS devices, despite reports of active exploitation attempts.

The situation shows the ongoing challenges in maintaining the security of older networking equipment and raises questions about manufacturers’ responsibilities towards users of legacy devices.

As cyber threats continue to evolve, users are increasingly caught between the need for up-to-date security and the desire to maximize the lifespan of their existing hardware.

Are you from SOC/DFIR Teams? – Analyse Malware & Phishing with ANY.RUN -> Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago