{"id":2036204,"date":"2024-11-13T12:22:08","date_gmt":"2024-11-13T17:22:08","guid":{"rendered":"https:\/\/securityboulevard.com\/?p=2036204"},"modified":"2024-11-13T12:22:08","modified_gmt":"2024-11-13T17:22:08","slug":"d-link-nas-wont-fix-richixbw","status":"publish","type":"post","link":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/","title":{"rendered":"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER"},"content":{"rendered":"<h5 style=\"text-align: center;\"><a href=\"#sbbwis\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full\" title=\"Her daughter is named Help I'm trapped in a driver's license factory. \u2014 Randall Munroe (cc:by-nc)\" src=\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png\" alt=\"xkcd.com\/327 \u2014 \u201cExploits of a Mom\u201d\" width=\"192\" height=\"75\" \/><\/a><strong>Company doesn\u2019t make storage devices now; has zero interest in fixing catastrophic\u202f\u202fvulnerability.<\/strong><\/h5>\n<p><strong>D-Link NAS boxes are obsolete. Even the youngest has been out of support for four years.<\/strong> That\u2019s why D-Link says it\u2019s not going to patch the latest critical flaw in its old range of network storage devices.<br \/>\n<!--br--><br \/>\n<strong>In fact, the firm claims it\u2019s \u201cprohibited\u201d from doing so.<\/strong> In today\u2019s <a href=\"https:\/\/securityboulevard.com\/tag\/sb-blogwatch\/\" target=\"_blank\" rel=\"noopener\">SB\u202f\u202fBlogwatch<\/a>, we find that bit kinda odd.<!--more--><br \/>\n<!--br--><br \/>\n<a title=\"Richi Jennings\" href=\"https:\/\/www.richi.uk\/\" target=\"_blank\" rel=\"noopener\">Your humble blog\u00adwatcher<\/a> curated these bloggy bits for your enter\u00adtain\u00adment. Not to mention:\u202f\u202f<i>SN#1000<\/i>.<br \/>\n<!--br--><\/p>\n<h2>\u2018Bobby\u2019 Flaw Flagged WONTFIX<\/h2>\n<p id=\"sbbw1\"><strong>What\u2019s the craic?<\/strong> Bill Toulas reports: <a title=\"read the full text\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">D-Link won\u2019t fix critical flaw affecting 60,000 older NAS devices<\/a><\/p>\n<p style=\"padding-left: 40px;\"><strong>\u201c<tt>Commonly used by small businesses<\/tt>\u201d<\/strong><br \/>\nCVE-2024-10914 has a critical [CVSS] 9.2 severity score and is present in the \u2018cgi_user_add\u2019 command. \u2026 An unauthenticated attacker could exploit it to inject arbitrary shell commands by sending specially crafted HTTP GET requests.<br \/>\n\u2026<br \/>\nThe flaw impacts multiple models of D-Link network-attached storage (NAS) devices that are commonly used by small businesses. \u2026 A fix for CVE-2024-10914 is not coming and the vendor recommends that users retire vulnerable products. \u2026 A D-Link spokesperson [said] the impacted products had reached EoL and will not be receiving security updates.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw2\"><strong>How many different products?<\/strong> Ionut Arghire usues all his fingers and toes: <a title=\"read the full text\" href=\"https:\/\/www.securityweek.com\/many-legacy-d-link-nas-devices-exposed-to-remote-attacks-via-critical-flaw\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">Many Legacy D-Link NAS Devices Exposed to Remote Attacks<\/a><\/p>\n<p style=\"padding-left: 40px;\">D-Link, however, warns that [20] discontinued NAS models are affected and that it cannot address the vulnerability, as all development and customer support have ceased. Some of these devices were retired a decade ago.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw4\"><strong>Who found it?<\/strong> NetworkSecurityFish: <a title=\"read the full text\" href=\"https:\/\/github.com\/netsecfish\/dlink\" target=\"_blank\" rel=\"nofollow ugc noopener\">Command Injection Vulnerability<\/a><\/p>\n<p style=\"padding-left: 40px;\">The vulnerability is localized to the account_mgr.cgi script, particularly in the handling of the cgi_user_add command. The name parameter in this script does not adequately sanitize input, allowing for command execution. [For] example:<br \/>\n\u2026<br \/>\n<strong><tt>curl \"http:\/\/[Target-IP]\/cgi-bin\/account_mgr.cgi?cmd=cgi_user_add&amp;name=%27;&lt;INJECTED_SHELL_COMMAND&gt;;%27\"<\/tt><\/strong><br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw3\"><strong>What does D-Link have to say for itself?<\/strong> Not a lot: <a title=\"read the full text\" href=\"https:\/\/supportannouncement.us.dlink.com\/security\/publication.aspx?name=SAP10413\" target=\"_blank\" rel=\"nofollow ugc noopener\">DNS-320 \/ DNS-325 \/ DNS-340L and all other D-Link NAS Models<\/a><\/p>\n<p style=\"padding-left: 40px;\"><strong>\u201c<tt>Latest firmware<\/tt>\u201d<\/strong><br \/>\nProducts that have reached their EOL\/EOS no longer receive device software updates and security patches and are no longer supported by D-Link. \u2026 D-Link&#8217;s general policy is that when products reach EOS\/EOL, they can no longer be supported, and all firmware development ceases.<br \/>\n\u2026<br \/>\nD-Link US is prohibited from providing support for these EOL\/EOS products, if you are outside the US, please contact your regional D-Link office. If your device was provided by a licensed carrier (service provider) and firmware, please contact your carrier.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw8\"><strong>Well, that sucks.<\/strong> <a title=\"read the full text\" href=\"https:\/\/www.reddit.com\/r\/hardware\/comments\/1gp1ewz\/dlink_says_it_wont_fix_a_serious_security_flaw\/lwofbqj\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">u\/JLeeSaxon<\/a> isn\u2019t happy:<\/p>\n<p style=\"padding-left: 40px;\">I can&#8217;t really agree with the, &#8220;It&#8217;s your fault for not throwing hardware that still runs fine in a landfill for no reason every September like Apple wants you to,&#8221; responses. \u2026 Don&#8217;t make it sound like some kind of age-based deterioration:\u202f\u2026\u202fThis flaw was always there and D-Link never found\/fixed it.<br \/>\n\u2026<br \/>\nNASA is still reprogramming Voyager 2, so let&#8217;s make sure we&#8217;re clear-eyed about the fact that these EOL decisions are 100% arbitrary and D-Link, <i>if they were willing<\/i>, would absolutely be able to do an emergency fix here given how widespread and serious this flaw apparently is.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw5\"><strong>How should we react to D-Link\u2019s attitude?<\/strong> <a title=\"read the full text\" href=\"https:\/\/it.slashdot.org\/comments.pl?sid=23517591&amp;cid=64938393\" target=\"_blank\" rel=\"nofollow ugc noopener\">gavron<\/a> waxes metaphorical:<\/p>\n<p style=\"padding-left: 40px;\">Carrots and Sticks: Reward vendors who support their products. Punish those who don&#8217;t.<br \/>\n\u2026<br \/>\nBecause of this,\u202f\u2026\u202fI will never buy a D-Link product again. Of any type. For any purpose. Not even for consulting clients.<br \/>\n\u2026<br \/>\nYou are welcome to join me. If someone says, &#8220;Hey this D-Link switch is cheaper,&#8221; just tell them how D-Link treats you <i>after<\/i> you give them your money, and eventually this will trickle down to lower quarterly earnings, less enjoyable shareholder 10Q reports, and they may get the message.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw6\"><strong>Why would owners have bought a D-Link NAS to begin with?<\/strong> <a title=\"read the full text\" href=\"https:\/\/forums.tomshardware.com\/threads\/d-link-refuses-to-patch-a-security-flaw-on-over-60-000-nas-devices-%E2%80%94-the-company-instead-recommends-replacing-legacy-nas-with-newer-models.3859905\/post-23369473\" target=\"_blank\" rel=\"nofollow ugc noopener\">Misgar<\/a> makes an important point:<\/p>\n<p style=\"padding-left: 40px;\">The answer might be that some D-Link NAS [were] less expensive than their QNAP and Synology counterparts. For some people, price is the overriding factor when making a purchase, regardless of any other factors. They might not be able to afford &#8220;better&#8221; products. They might be blissfully unaware of the weaknesses, or just not care.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw7\"><strong>Any other reasons?<\/strong> <a title=\"read the full text\" href=\"https:\/\/news.ycombinator.com\/item?id=42120518\" target=\"_blank\" rel=\"nofollow ugc noopener\">thesnide<\/a> offers some:<\/p>\n<p style=\"padding-left: 40px;\">The hardware was cheap and decent. The software is nicely hackable.<br \/>\n\u2026<br \/>\nI did strip all the D-Link firmware to replace it with a trimmed down one. Works flawlessly since day one. And that&#8217;s a long time [ago].<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw9\"><strong>This sounds like a job for open source.<\/strong> <a title=\"read the full text\" href=\"https:\/\/www.reddit.com\/r\/technology\/comments\/1gpa8i4\/dlink_says_it_wont_fix_a_serious_security_flaw\/lwp2w2o\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">u\/DGolden<\/a> agrees:<\/p>\n<p style=\"padding-left: 40px;\">It looks like people have worked out how to stick Linux \/ Debian \/ OpenWRT on at least some models:<br \/>\n<a href=\"https:\/\/jamie.lentin.co.uk\/devices\/dlink-dns325\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">https:\/\/jamie.lentin.co.uk\/devices\/dlink-dns325\/<\/a><br \/>\n<a href=\"https:\/\/www.aboehler.at\/doku\/doku.php\/projects:dns320l\" target=\"_blank\" rel=\"nofollow ugc noopener\">https:\/\/www.aboehler.at\/doku\/doku.php\/projects:dns320l<\/a><br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw12\"><strong>Meanwhile,<\/strong> speaking of FLOSS, <a title=\"read the full text\" href=\"https:\/\/it.slashdot.org\/comments.pl?sid=23517591&amp;cid=64938923\" target=\"_blank\" rel=\"nofollow ugc noopener\">Wokan<\/a> has excellent gum health:\u00a0<em>[You\u2019re fired\u2014Ed.]<\/em><\/p>\n<p style=\"padding-left: 40px;\">Meanwhile, 12 years later, my TrueNAS Scale\u202f\u2026\u202fbox running on a 2012 CPU is still serving up files and getting regular updates. If you want to have a NAS you pay for once and then not subscribe to, roll up your sleeves and learn a little DIY.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<h4 id=\"sbbwaf\">And Finally:<\/h4>\n<p><b><a title=\"And Finally\" href=\"https:\/\/www.youtube.com\/watch?v=o1MaEuxGQJk&amp;list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" target=\"_blank\" rel=\"noopener\">Love him or loathe him, you can\u2019t deny Steve Gibson is \u2026 old<\/a><\/b><script async defer src=\"https:\/\/scripts.withcabin.com\/hello.js\"><\/script><!-- zero-cookie analytics privacy: https:\/\/withcabin.com\/privacy\/securityboulevard.com --><\/p>\n<div class=\"jetpack-video-wrapper\">\n<div class=\"fitvids-video\"><iframe loading=\"lazy\" title=\"1000 Episodes of Security Now\" width=\"800\" height=\"450\" src=\"https:\/\/www.youtube.com\/embed\/o1MaEuxGQJk?list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<\/div>\n<p><a href=\"https:\/\/www.youtube.com\/playlist?list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" target=\"_blank\" rel=\"noopener\">Previously in <em>And Finally<\/em><\/a><\/p>\n<hr \/>\n<p><em>You have been reading <i>SB\u202fBlogwatch<\/i> by <a href=\"https:\/\/www.richi.uk\/\" target=\"_blank\" rel=\"noopener\">Richi\u202fJennings<\/a>. Richi curates the best bloggy bits, finest forums, and weird\u00adest web\u00adsites\u2014so you don\u2019t have to. Hate mail may be directed to\u202f\u202f<a href=\"https:\/\/twitter.com\/richi\" target=\"_blank\" rel=\"nofollow ugc noopener\">@RiCHi<\/a>, <a href=\"https:\/\/threads.net\/@richij\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richij<\/a>, <a href=\"https:\/\/vmst.io\/deck\/@richi\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richi@vmst.io<\/a>, <a href=\"https:\/\/bsky.app\/profile\/richi.bsky.social\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richi.bsky.social<\/a> or <a href=\"mailto:sbbw@richi.co.uk?subject=-sbbw-\">sbbw@richi.uk<\/a>. Ask your doctor before reading. Your mileage may vary. Past per\u00adformance is no guar\u00adantee of future results. Do not stare into laser with re\u00admaining eye. E&amp;OE. 30.<\/em><\/p>\n<p>Image sauce: <a href=\"https:\/\/xkcd.com\/327\/\" target=\"_blank\" rel=\"noopener\" name=\"sbbwis\">Randall Munroe<\/a> (<a title=\"Some rights reserved\" href=\"https:\/\/creativecommons.org\/licenses\/by-sa\/2.5\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">cc:by-nc<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.<\/p>\n","protected":false},"author":8670,"featured_media":2036205,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[590,23406,98344,13571,21858,21028,24367,308,20984,30691,651,35889,14089,14098,35458,30205,14097,98631,99462,99461,13418,21129,497],"tags":[104287,12626,95381,101755,83533,83517,14064,58786,75349,88301,14105,28654,104288,57759],"class_list":["post-2036204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security","category-blogs","category-data-privacy","category-data-security","category-sb-featured","category-governance-risk-compliance","category-humor","category-identity-access","category-incident-response","category-sb-industry-spotlight","category-iot-ics-security","category-most-read-this-week","category-network-security","category-sb-news","category-popular-post","category-security-awareness","category-sb","category-social-facebook","category-social-linkedin","category-social-x","category-sb-spotlight","category-threats-breaches","category-vulnerabilities","tag-cve-2024-10914","tag-d-link","tag-d-link-corporation","tag-d-link-nas-devices","tag-d-link-vulnerability","tag-d-link-zero-day","tag-internet-of-things","tag-internet-of-things-iot","tag-internet-of-things-iot-security","tag-internet-of-things-cyber-security","tag-iot","tag-nas","tag-network-storage-device","tag-sb-blogwatch"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.9 (Yoast SEO v23.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER - Security Boulevard<\/title>\n<meta name=\"description\" content=\"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER\" \/>\n<meta property=\"og:description\" content=\"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\" \/>\n<meta property=\"og:site_name\" content=\"Security Boulevard\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/groups\/24445075146\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/richij\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-13T17:22:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Richi Jennings\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@RiCHi\" \/>\n<meta name=\"twitter:site\" content=\"@securityblvd\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\",\"url\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\",\"name\":\"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER - Security Boulevard\",\"isPartOf\":{\"@id\":\"https:\/\/securityboulevard.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png\",\"datePublished\":\"2024-11-13T17:22:08+00:00\",\"dateModified\":\"2024-11-13T17:22:08+00:00\",\"author\":{\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100\"},\"description\":\"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.\",\"breadcrumb\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage\",\"url\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png\",\"contentUrl\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png\",\"width\":770,\"height\":300,\"caption\":\"xkcd.com\/327 \u2014 \u201cExploits of a Mom\u201d\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/securityboulevard.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Boulevard (Original)\",\"item\":\"https:\/\/securityboulevard.com\/category\/sb\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"News\",\"item\":\"https:\/\/securityboulevard.com\/category\/sb\/sb-news\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/securityboulevard.com\/#website\",\"url\":\"https:\/\/securityboulevard.com\/\",\"name\":\"Security Boulevard\",\"description\":\"The Home of the Security Bloggers Network\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/securityboulevard.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100\",\"name\":\"Richi Jennings\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g\",\"caption\":\"Richi Jennings\"},\"description\":\"Richi Jennings is a foolish independent industry analyst, editor, and content strategist. A former developer and marketer, he\u2019s also written or edited for Computerworld, Microsoft, Cisco, Micro Focus, HashiCorp, Ferris Research, Osterman Research, Orthogonal Thinking, Native Trust, Elgan Media, Petri, Cyren, Agari, Webroot, HP, HPE, NetApp on Forbes and CIO.com. Bizarrely, his ridiculous work has even won awards from the American Society of Business Publication Editors, ABM\/Jesse H. Neal, and B2B Magazine.\",\"sameAs\":[\"https:\/\/richi.uk\",\"https:\/\/www.facebook.com\/richij\",\"https:\/\/www.linkedin.com\/in\/richi\/\",\"https:\/\/x.com\/RiCHi\",\"https:\/\/www.youtube.com\/c\/richijennings\",\"https:\/\/en.wikipedia.org\/wiki\/User:Richi\"],\"url\":\"https:\/\/securityboulevard.com\/author\/richi\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER - Security Boulevard","description":"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/","og_locale":"en_US","og_type":"article","og_title":"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER","og_description":"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.","og_url":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/","og_site_name":"Security Boulevard","article_publisher":"https:\/\/www.facebook.com\/groups\/24445075146\/","article_author":"https:\/\/www.facebook.com\/richij","article_published_time":"2024-11-13T17:22:08+00:00","og_image":[{"width":770,"height":300,"url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png","type":"image\/png"}],"author":"Richi Jennings","twitter_card":"summary_large_image","twitter_creator":"@RiCHi","twitter_site":"@securityblvd","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/","url":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/","name":"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER - Security Boulevard","isPartOf":{"@id":"https:\/\/securityboulevard.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage"},"image":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage"},"thumbnailUrl":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png","datePublished":"2024-11-13T17:22:08+00:00","dateModified":"2024-11-13T17:22:08+00:00","author":{"@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100"},"description":"\u2018Bobby\u2019 flaw flagged WONTFIX: Company doesn\u2019t make storage devices now; has zero interest in fixing this catastrophic vulnerability.","breadcrumb":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#primaryimage","url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png","contentUrl":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png","width":770,"height":300,"caption":"xkcd.com\/327 \u2014 \u201cExploits of a Mom\u201d"},{"@type":"BreadcrumbList","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securityboulevard.com\/"},{"@type":"ListItem","position":2,"name":"Security Boulevard (Original)","item":"https:\/\/securityboulevard.com\/category\/sb\/"},{"@type":"ListItem","position":3,"name":"News","item":"https:\/\/securityboulevard.com\/category\/sb\/sb-news\/"},{"@type":"ListItem","position":4,"name":"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER"}]},{"@type":"WebSite","@id":"https:\/\/securityboulevard.com\/#website","url":"https:\/\/securityboulevard.com\/","name":"Security Boulevard","description":"The Home of the Security Bloggers Network","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securityboulevard.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100","name":"Richi Jennings","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g","caption":"Richi Jennings"},"description":"Richi Jennings is a foolish independent industry analyst, editor, and content strategist. A former developer and marketer, he\u2019s also written or edited for Computerworld, Microsoft, Cisco, Micro Focus, HashiCorp, Ferris Research, Osterman Research, Orthogonal Thinking, Native Trust, Elgan Media, Petri, Cyren, Agari, Webroot, HP, HPE, NetApp on Forbes and CIO.com. Bizarrely, his ridiculous work has even won awards from the American Society of Business Publication Editors, ABM\/Jesse H. Neal, and B2B Magazine.","sameAs":["https:\/\/richi.uk","https:\/\/www.facebook.com\/richij","https:\/\/www.linkedin.com\/in\/richi\/","https:\/\/x.com\/RiCHi","https:\/\/www.youtube.com\/c\/richijennings","https:\/\/en.wikipedia.org\/wiki\/User:Richi"],"url":"https:\/\/securityboulevard.com\/author\/richi\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/sanitize-inputs-richixbw-xkcd-cc-by-nc.png","jetpack_shortlink":"https:\/\/wp.me\/p91vu9-8xI0","_links":{"self":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2036204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/users\/8670"}],"replies":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/comments?post=2036204"}],"version-history":[{"count":3,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2036204\/revisions"}],"predecessor-version":[{"id":2036216,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2036204\/revisions\/2036216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/media\/2036205"}],"wp:attachment":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/media?parent=2036204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/categories?post=2036204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/tags?post=2036204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}