D-Link won't patch a remote exploit in four of its routers, saying they are end-of-life, despite some being discontinued in 2018 and still being sold on Amazon
Paul Wagenseil / Tom's Guide :
Context & Ripple Effects
D-Link's refusal to patch a remote exploit in four routers extends a pattern the company already knows well: the FTC sued D-Link in 2017 over hard-coded logins and exposed sign-in key code in the same product lines. What is new is the gap between the end-of-life label and reality — some of these routers were discontinued only in 2018 and are still listed on Amazon.
The wider industry context is unflattering. Netgear faced a critical remotely-exploitable router flaw in 2016, Belkin's routers carried unpatched flaws in 2015, and a Fraunhofer Institute study later found 46 of 127 home routers across 7 brands received zero updates in a year. D-Link's stance makes the patch-or-retire question a consumer-facing issue, not just a security-shop one.
First-order effects
- Owners of the four affected D-Link routers are left with a remotely exploitable device and no fix, and some can still buy the hardware new on Amazon without any patch commitment disclosed at point of sale.
Second-order effects
- Retailers like Amazon become the de facto enforcement point: continued sales of unpatched hardware invite pressure to delist or label end-of-life devices, and rivals such as Netgear — burned by a critical remote flaw of its own — can differentiate on patch longevity.
Third-order effects
- If end-of-life continues to mean unpatched-but-still-sold, expect regulators and standards bodies to push toward mandatory disclosure of support windows at purchase, turning router firmware maintenance into a stated product obligation rather than a courtesy.
The trend: Consumer router security is shifting from voluntary vendor patching toward explicit support-lifetime commitments, as regulators and studies document how long unpatched devices stay in homes and on store shelves.