HomeSecurityD-Link: Will not fix new vulnerabilities in DIR-846W router

D-Link: Will not fix new vulnerabilities in DIR-846W router

D -Link is warning about four vulnerabilities in the DIR-846W routerthat could allow remote code execution (RCE). The vulnerabilities affect all hardware and firmware versions of the DIR-846W router, but D-Link does not plan to take action to fix them, as the products are no longer supported.

D-Link DIR-846W router vulnerabilities

The four vulnerabilities were discovered by security researcher yali-1002 . Three are rated critical and do not require authentication . The researcher published the information on his GitHub repository , but has withheld the publication of proof-of-concept (PoC) exploits (for now).

See also: Zyxel fixes critical vulnerability in routers

According to D-Link, the vulnerabilities in the DIR-846W router are as follows: CVE-2024-41622 (CVSS v3: 9.8), CVE-2024-44340 (CVSS v3 8.8), CVE-2024-44341(CVSS v3: 9.8) and CVE-2024-44342 (CVSS v3: 9.8).

Although D-Link acknowledged the security issues and their severity, it explained that they fall under end-of-life/end-of-support policies, which means that updates to address them.

"As a general policy, when products (e.g. DIR-846W router) reach EOS/EOL, they can no longer be supported and all firmware development for these products stops," D-Link's announcement states.

See also: Hackers exploit vulnerability in D-Link DIR-859 routers

D-Link is urging customers to stop using the DIR-846W router, as its use may pose a risk to devices connected to it.

Although the DIR-846 router was discontinued in 2020, many users may still be using it. It is common to replace a router when a hardware problem occurs, but in reality, we should be much more concerned about security.

D-Link: Will not fix new vulnerabilities in DIR-846W router
D: Will not fix new vulnerabilities in DIR-846W router

D-Link recommends that people still using the DIR-846 immediately retire it and purchase a newer model.

See also: Critical vulnerability puts D-Link routers at risk

General router protection tips:

1. Update firmware regularly

2. Change the default login credentials

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

3. Use a strong password

4. Enable encryption

5. Disable remote management 

6. Set up a guest Wi-Fi network

7. Use a firewall

8. Monitor connected devices on the DIR-846W router

9. Keep the router in a safe place

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS