D -Link is warning about four vulnerabilities in the DIR-846W routerthat could allow remote code execution (RCE). The vulnerabilities affect all hardware and firmware versions of the DIR-846W router, but D-Link does not plan to take action to fix them, as the products are no longer supported.

The four vulnerabilities were discovered by security researcher yali-1002 . Three are rated critical and do not require authentication . The researcher published the information on his GitHub repository , but has withheld the publication of proof-of-concept (PoC) exploits (for now).
See also: Zyxel fixes critical vulnerability in routers
According to D-Link, the vulnerabilities in the DIR-846W router are as follows: CVE-2024-41622 (CVSS v3: 9.8), CVE-2024-44340 (CVSS v3 8.8), CVE-2024-44341(CVSS v3: 9.8) and CVE-2024-44342 (CVSS v3: 9.8).
Although D-Link acknowledged the security issues and their severity, it explained that they fall under end-of-life/end-of-support policies, which means that updates to address them.
"As a general policy, when products (e.g. DIR-846W router) reach EOS/EOL, they can no longer be supported and all firmware development for these products stops," D-Link's announcement states.
See also: Hackers exploit vulnerability in D-Link DIR-859 routers
D-Link is urging customers to stop using the DIR-846W router, as its use may pose a risk to devices connected to it.
Although the DIR-846 router was discontinued in 2020, many users may still be using it. It is common to replace a router when a hardware problem occurs, but in reality, we should be much more concerned about security.

D-Link recommends that people still using the DIR-846 immediately retire it and purchase a newer model.
See also: Critical vulnerability puts D-Link routers at risk
General router protection tips:
1. Update firmware regularly
2. Change the default login credentials
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
3. Use a strong password
4. Enable encryption
5. Disable remote management
6. Set up a guest Wi-Fi network
7. Use a firewall
8. Monitor connected devices on the DIR-846W router
9. Keep the router in a safe place
Source: www.bleepingcomputer.com
