Skip to main content
  1. Home
  2. Computing
  3. News

Some older D-Link routers are vulnerable to attack

Add as a preferred source on Google
A Wi-Fi router with an ethernet cable plugged in.
Getty Images

A few legacy D-Link routers can be vulnerable to Remote Code Execution (RCE) attacks since the company refuses to send any updates to patch them up, claiming they have reached end-of-life, as recently posted on its announcement page.

The vulnerability is a serious issue since it allows hackers to take control from anywhere in the world and use a stack buffer overflow. This attack sends more data than the buffer size can handle, potentially corrupting critical information like the return address. Thus, hackers can take control of your PC. However, the company did not detail how the threat works, possibly not informing the hackers too much about the issue.

Recommended Videos

The lack of a fix puts users at risk since they are exposed to malware, data theft, spyware installation, DoS attacks, and more. The routers that are at risk include the following:

  • DSR-150
  • DSR-150N
  • DSR-250
  • DSR-250N
  • DSR-500N
  • DSR-1000N

The company’s only solution for those affected is to get a new router, and if that’s what you’re going to do, you may as well buy one of the best routers. Unfortunately, though, four of the listed routers were discontinued this year, which is bad news considering D-Link said, “If a product has reached End of Support (“EOS”) / End of Life (“EOL”), there is normally no further extended support or development for it.”

The 20% discount D-Link offers on new routers is a nice gesture, but the report says many of the listed routers are open to third-party firmware. That’s not a great solution since it voids the warranty.

But let’s face it: when a device becomes obsolete, it makes sense that the company wants to forget about it and concentrate on the new models.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
A simple coding mistake is exposing API keys across thousands of websites
Security gaps that are easier to miss than you think
Computer, Electronics, Laptop

After analyzing 10 million webpages, researchers have found thousands of websites accidentally exposing sensitive API credentials, including keys linked to major services like Amazon Web Services, Stripe, and OpenAI.

This is a serious issue because APIs act as the backbone of the apps we use today. They allow websites to connect to services like payments, cloud storage, and AI tools, but they rely on digital keys to stay secure. Once exposed, API keys can allow anyone to interact with those services with malicious intent.

Read more
AMD’s latest Ryzen 9 9950X3D2 pushes X3D to the limit
Dual 3D V-Cache, higher power, and a focus on enthusiast performance
AMD Ryzen 9 9950X3D2 FEatured

AMD has unveiled what might be its most extreme desktop CPU yet, the Ryzen 9 9950X3D2. And it’s going all-in on one thing: cache.

https://twitter.com/jackhuynh/status/2037159705395491033?s=20

Read more
Next-gen AI breakthrough promises chatbots that can read the room better
Researchers are teaching AI chatbots to read between the lines
Generative AI

Have you ever asked a chatbot something and felt like it completely missed your point? You say something with a bit of nuance, and the AI misses the subtlety entirely. That is exactly the problem researchers are trying to solve.

Even though the emotional connection with AI can feel deeper than human conversation for many users, most AI systems today still treat a sentence as a single block of sentiment. If you mix praise and criticism, the nuance often gets lost.

Read more