D-Link has released firmware updates for its DIR-820L router model , following a report by an independent security researcher who found several security vulnerabilities in the device, one of which allows a remote source to gain access and control over the network .
Researcher Peter Adkins discovered the vulnerabilities and notified the company on January 11, but the manufacturer did not respond within the required timeframe, so the researcher made his findings public on February 26.
Last Monday, D-Link released a security advisory informing that after the company's investigation, the DIR-626L/DIR-636L/DIR-808L/DIR-810L/DIR-826L/DIR-830L/DIR-836 router models were also found to have similar security vulnerabilities.
The new firmware was officially released on Thursday and is available for the DIR – 820L model, while it is estimated that updates for the remaining devices will be released by March 10.
The most dangerous problem uncovered by Adkins is gaining root access to the router via CSRF, tricking the user into entering a malware-ridden website.
This will allow unauthorized access to the DNS (domain name system) configuration, which is designed to direct the device to a server responsible for converting names to IP addresses so that the user is directed to the appropriate website via the browser.
The company recommends downloading and installing the updates as soon as they are released. Until then, and for those models of the company that have not yet received the updates, it is recommended to disable the WAN function so that someone cannot access the management from a remote network.

