D -Link is warning customers to replace VPN router models that are no longer supported by the company (EoL), after a serious vulnerability that will not be patched and therefore puts systems at risk.

The vulnerability was discovered and reported to D-Link by security researcher "delsploit." Technical details have not been published to prevent mass exploitation by hackers.
See also: Apple fixes zero-day vulnerabilities in Mac systems
The vulnerability affects all hardware and firmware revisions of the DSR-150 and DSR-150N, as well as the DSR-250 and DSR-250N from firmware 3.13 to 3.17B901C.
These VPN routers are quite popular among home consumers and small businesses, but they stopped being supported by the company on May 1, 2024.
D-Link has made it clear that it will not be releasing a security update for these four VPN router models and is therefore recommending that customers replace the devices as soon as possible.
See also: VMware vCenter Server: Critical vulnerability used in attacks
The company also notes that there may be third-party open-firmware for these devices, but this is an unsupported and not officially recommended. Using such software voids any warranty covering the product.

“D-Link strongly recommends the recall of these products and warns that any further use of them may pose a risk to devices connected to them,” states .
“If US consumers continue to use these devices despite D-Link's recommendation, they should ensure that the device has at least the latest known firmware which can be found on the Legacy Website.“.
See also: Palo Alto Networks patches two zero-day firewall vulnerabilities
However, this will not protect D-Link VPN routers.
General VPN router protection tips:
1. Update firmware regularly
2. Change the default login credentials
3. Use a strong password
4. Enable encryption
5. Disable remote management
6. Use a firewall
8. Monitor connected devices
Source: www.bleepingcomputer.com
