/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

D-Link won't patch a remote exploit in four of its routers, saying they are end-of-life, despite some being discontinued in 2018 and still being sold on Amazon

Paul Wagenseil / Tom's Guide :

Tom's Guide Paul Wagenseil

Context & Ripple Effects

D-Link's refusal to patch a remote exploit in four routers extends a pattern the company already knows well: the FTC sued D-Link in 2017 over hard-coded logins and exposed sign-in key code in the same product lines. What is new is the gap between the end-of-life label and reality — some of these routers were discontinued only in 2018 and are still listed on Amazon.

The wider industry context is unflattering. Netgear faced a critical remotely-exploitable router flaw in 2016, Belkin's routers carried unpatched flaws in 2015, and a Fraunhofer Institute study later found 46 of 127 home routers across 7 brands received zero updates in a year. D-Link's stance makes the patch-or-retire question a consumer-facing issue, not just a security-shop one.

First-order effects

  • Owners of the four affected D-Link routers are left with a remotely exploitable device and no fix, and some can still buy the hardware new on Amazon without any patch commitment disclosed at point of sale.

Second-order effects

  • Retailers like Amazon become the de facto enforcement point: continued sales of unpatched hardware invite pressure to delist or label end-of-life devices, and rivals such as Netgear — burned by a critical remote flaw of its own — can differentiate on patch longevity.

Third-order effects

  • If end-of-life continues to mean unpatched-but-still-sold, expect regulators and standards bodies to push toward mandatory disclosure of support windows at purchase, turning router firmware maintenance into a stated product obligation rather than a courtesy.

The trend: Consumer router security is shifting from voluntary vendor patching toward explicit support-lifetime commitments, as regulators and studies document how long unpatched devices stay in homes and on store shelves.

Discussion

  • @mr_internet @mr_internet on x
    Why I am concerned over ever suggesting some suppliers like @Dlink https://twitter.com/...
  • @dd42bb @dd42bb on x
    @Techmeme @snd_wagenseil People should use their old PC hardware for a router and install Pfsense and the like. The end of life span is getting shorter and shorter as a ploy to force people to replace old functional hardware with new.
  • @pblakez @pblakez on x
    why would anyone buy @dlink anymore decades of vulnerabilities they never seem to learn or care https://twitter.com/...
  • @jedisct1 Frank Denis on x
    Install OpenWRT / OverTheBox / MPTCPRouter / Tomato /... Stock firmware sucks. > D-Link Home Routers Open to Remote Takeover Will Remain Unpatched https://threatpost.com/...
  • @kaspersky @kaspersky on x
    Vulnerability CVE-2019-16920 which allows an attacker to remotely take over and execute code in several D-Link home wi-fi routers will remain unpatched. https://threatpost.com/...