{"id":2037237,"date":"2024-11-21T12:33:40","date_gmt":"2024-11-21T17:33:40","guid":{"rendered":"https:\/\/securityboulevard.com\/?p=2037237"},"modified":"2024-11-21T12:33:40","modified_gmt":"2024-11-21T17:33:40","slug":"d-link-router-critical-rce-sol-richixbw","status":"publish","type":"post","link":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/","title":{"rendered":"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed"},"content":{"rendered":"<h5 style=\"text-align: center;\"><a href=\"#sbbwis\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full\" src=\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw-130x90.png\" alt=\"A D-Link DSR-250N, which is now EOL\" width=\"130\" height=\"90\" \/><\/a><strong>Stubborn network device maker digs in heels and tells you to buy\u202f\u202fnew\u202f\u202fgear.<\/strong><\/h5>\n<p><strong>D-Link is <em>once again<\/em> under fire for not patching critical vulns.<\/strong> As with <a title=\"These 20 D-Link Devices Have Critical RCE Bug \u2014 but NO Patch NEVER\" href=\"https:\/\/securityboulevard.com\/2024\/11\/d-link-nas-wont-fix-richixbw\/\" target=\"_blank\" rel=\"noopener\">last week\u2019s D-Link d\u00e9b\u00e2cle<\/a>, the firm\u2019s digging in its heels because the devices are a few months past their arbitrary end-of-life date (EOL).<br \/>\n<!--br--><br \/>\n<strong>This week, it\u2019s a buffer overflow in six router products.<\/strong> In today\u2019s <a href=\"https:\/\/securityboulevard.com\/tag\/sb-blogwatch\/\" target=\"_blank\" rel=\"noopener\">SB\u202f\u202fBlogwatch<\/a>, we wonder what next week\u2019s will be.<!--more--><br \/>\n<!--br--><br \/>\n<a title=\"Richi Jennings\" href=\"https:\/\/www.richi.uk\/\" target=\"_blank\" rel=\"noopener\">Your humble blog\u00adwatcher<\/a> curated these bloggy bits for your enter\u00adtain\u00adment. Not to mention:\u202f\u202f<i>Science!<\/i><br \/>\n<!--br--><\/p>\n<h2>D-Licious<\/h2>\n<p id=\"sbbw1\"><strong>What\u2019s the craic?<\/strong> Bill Toulas reports: <a title=\"read the full text\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/d-link-urges-users-to-retire-vpn-routers-impacted-by-unfixed-rce-flaw\/\" target=\"_blank\" rel=\"nofollow ugc noopener\">D-Link urges users to retire VPN routers impacted by unfixed RCE flaw<\/a><\/p>\n<p style=\"padding-left: 40px;\"><strong>\u201c<tt>Critical flaws<\/tt>\u201d<\/strong><br \/>\nThe vulnerability\u202f\u2026\u202fimpacts all hardware and firmware revisions of DSR-150 and DSR-150N, and also DSR-250 and DSR-250N from firmware 3.13 to 3.17B901C. These VPN routers, popular in home office and small business set\u00adt\u00adings,\u202f\u2026\u202freached their end of service on May 1.<br \/>\n\u2026<br \/>\nD-Link has made it clear\u202f\u2026\u202fthey will not be releasing a security update. [It is] the networking hardware vendor&#8217;s strategy not to make exceptions for EoL devices when critical flaws are discovered, no matter how many people are still using these devices.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw2\"><strong>What are we supposed to do about it?<\/strong> Sead Fadilpa\u0161i\u0107 has more: <a title=\"read the full text\" href=\"https:\/\/www.techradar.com\/pro\/security\/d-link-is-telling-users-to-stop-using-these-routers-immediately-or-face-hacking\" target=\"_blank\" rel=\"nofollow ugc noopener\">D-Link is telling users to stop using these routers immediately, or face hacking<\/a><\/p>\n<p style=\"padding-left: 40px;\"><strong>\u201c<tt>Criminals will try to compromise<\/tt>\u201d<\/strong><br \/>\nD-Link said that both hardware and firmware for these devices have expired, and workarounds are not recommended. \u2026 Instead, it urged users to retire the affected devices and replace them with newer, supported models.<br \/>\n\u2026<br \/>\nOnce word gets out, cybercriminals will definitely start scanning for vulnerable routers. \u2026 Being the gateways of all internet traffic on a local network, [they] are usually the first thing criminals will try to compromise in their attacks. End-of-life devices with known critical vulnerabilities, especially RCE, are considered low hanging fruit.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw3\"><strong>Horse\u2019s mouth?<\/strong> <a title=\"read the full text\" href=\"https:\/\/supportannouncement.us.dlink.com\/security\/publication.aspx?name=SAP10415\" target=\"_blank\" rel=\"nofollow ugc noopener\">Please Retire and Replace &#8211; Reported Security Vulnerabilities<\/a>:<\/p>\n<p style=\"padding-left: 40px;\"><strong>\u201c<tt>Recommends that this product be retired<\/tt>\u201d<\/strong><br \/>\nThis exploit affects this legacy D-Link router and all hardware revisions, which have reached their End of Life (&#8220;EOL&#8221;)\/End of Service Life (&#8220;EOS&#8221;) Life-Cycle. Products that have reached their EOL\/EOS no longer receive device software updates and security patches and are no longer supported by D-Link. \u2026 When products reach EOS\/EOL, they can no longer be supported, and all firmware development for these products cease.<br \/>\n\u2026<br \/>\nD-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it. \u2026 If you are an owner of a D-Link Model listed below and live in the US, D-Link will offer you a new DSR-250v2\u202f\u2026\u202ffor 20% off. \u2026 Affected Models: DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw4\"><strong>Less PR flim-flam, please.<\/strong> <a title=\"read the full text\" href=\"https:\/\/forums.theregister.com\/forum\/all\/2024\/11\/20\/dlink_rip_replace_router\/#c_4969402\" target=\"_blank\" rel=\"nofollow ugc noopener\">Mentat74<\/a> translates for us:<\/p>\n<p style=\"padding-left: 40px;\">\u201cOur old products are **** and full of security holes that we won&#8217;t patch. Please buy our new products!\u201d<br \/>\n\u2026<br \/>\nAlso:\u202f\u2026\u202fHow convenient that this particular bug has been discovered so soon [after] EOL.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw5\"><strong>D-Link doesn\u2019t look so good.<\/strong> <a title=\"read the full text\" href=\"https:\/\/it.slashdot.org\/comments.pl?sid=23526627&amp;cid=64960403\" target=\"_blank\" rel=\"nofollow ugc noopener\">NewtonsLaw<\/a> seconds the motion:\u00a0<em>[You\u2019re fired\u2014Ed.]<\/em><\/p>\n<p style=\"padding-left: 40px;\">Seriously? \u2026 D-Link just signed its own death-warrant.<br \/>\n\u2026<br \/>\nWho in their right mind would buy or use any product bearing the D-Link brand if this is the way they deal with flaws in their products that compromise the security and integrity of users&#8217; systems? <i>What are they smoking?<\/i><br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw6\"><strong>Be vewwy, vewwy qwiet!<\/strong> <a title=\"read the full text\" href=\"https:\/\/news.ycombinator.com\/item?id=42201907\" target=\"_blank\" rel=\"nofollow ugc noopener\">elmerfud<\/a>\u2019s huntin\u2019 wegulation:<\/p>\n<p style=\"padding-left: 40px;\">This is where I wish governments would step in and stop allowing companies to make appliances that are throw away. I understand that a company can only viably support or offer warranty for a limited time period but that should not cause something to become trash when [EOL].<br \/>\n\u2026<br \/>\nThe right to repair movement focuses mostly on the actual repair of the item but when so many of these items are using microcontrollers that are running software code,\u202f\u2026\u202fthe right to repair the hardware itself is insufficient. The United States is too dumb and too controlled by businesses to pass any meaningful legislation but I would hope that the EU would step up and pass legislation that says when you EOL a prod\u00aduct\u202f\u2026\u202frun\u00adn\u00ading software code, you must also open source [it] along with all appropriate tooling. \u2026 This way the community can continue to repair these devices.<br \/>\n\u2026<br \/>\nOne other thing that should be considered is that, even though this is an end of life product, this was a defect that existed from the beginning of the life of this product. Therefore this was defective the entire time\u2014it just wasn&#8217;t discovered until now. This is another area a legislators need to step in and correct. Automobiles have no time limit on a safety recall. \u2026 It doesn&#8217;t matter if it took 15 years to be dis\u00adcov\u00adered,\u202f\u2026\u202fthe manufacturer is required to correct it.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw7\"><strong>But is anyone paying attention?<\/strong> <a title=\"read the full text\" href=\"https:\/\/www.theverge.com\/2024\/11\/20\/24301924\/if-you-have-one-of-these-d-link-routers-you-need-to-replace-it-now?commentID=c6ab0c7d-2180-45c2-973f-dcb1e2fb59c3\" target=\"_blank\" rel=\"nofollow ugc noopener\">MoMonies<\/a> thinks not:<\/p>\n<p style=\"padding-left: 40px;\">Chances are that any business that is still using this is completely unaware that they have [one] and that it is now extremely vulnerable.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw8\"><strong>However,<\/strong> <a title=\"read the full text\" href=\"https:\/\/forums.tomshardware.com\/threads\/d-link-refuses-to-patch-yet-another-security-flaw-suggests-users-just-buy-new-routers-%E2%80%94-d-link-told-users-to-replace-nas-last-week.3861166\/post-23376079\" target=\"_blank\" rel=\"nofollow ugc noopener\">bill001g<\/a> doesn\u2019t agree:<\/p>\n<p style=\"padding-left: 40px;\">They are basically e-waste. Who is really going to be running a router with 100mbps ports nowadays? Commercial equipment is generally replaced long before it hits end of life.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<p id=\"sbbw9\"><strong>Meanwhile,<\/strong> where does the company get its name? <a title=\"read the full text\" href=\"https:\/\/forums.theregister.com\/forum\/all\/2024\/11\/20\/dlink_rip_replace_router\/#c_4969634\" target=\"_blank\" rel=\"nofollow ugc noopener\">Mitoo Bobsworth<\/a> has often wondered that:<\/p>\n<p style=\"padding-left: 40px;\">D for Dud? I often wondered what it stood for.<br \/>\n<!-----------------------------------------------------------------------------><\/p>\n<h4 id=\"sbbwaf\">And Finally:<\/h4>\n<p><b><a title=\"And Finally\" href=\"https:\/\/www.youtube.com\/watch?v=h90rEkbx95w&amp;list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" target=\"_blank\" rel=\"noopener\">Don\u2019t try this at home, kids<\/a><\/b><script async defer src=\"https:\/\/scripts.withcabin.com\/hello.js\"><\/script><!-- zero-cookie analytics privacy: https:\/\/withcabin.com\/privacy\/securityboulevard.com --><\/p>\n<div class=\"jetpack-video-wrapper\">\n<div class=\"fitvids-video\"><iframe loading=\"lazy\" title=\"I fixed my lactose intolerance -- by chugging ALL the lactose\" width=\"800\" height=\"450\" src=\"https:\/\/www.youtube.com\/embed\/h90rEkbx95w?list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<\/div>\n<p>Hat tip: <a href=\"https:\/\/www.tomscott.com\/newsletter\/2024-11-18\/\" target=\"_blank\" rel=\"noopener\">Tom Scott<\/a><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/playlist?list=PL9zSC5i495YMjIuJjxToNGU8Ve7Gd5Rvj\" target=\"_blank\" rel=\"noopener\">Previously in <em>And Finally<\/em><\/a><\/p>\n<hr \/>\n<p><em>You have been reading <i>SB\u202fBlogwatch<\/i> by <a href=\"https:\/\/www.richi.uk\/\" target=\"_blank\" rel=\"noopener\">Richi\u202fJennings<\/a>. Richi curates the best bloggy bits, finest forums, and weird\u00adest web\u00adsites\u2014so you don\u2019t have to. Hate mail may be directed to\u202f\u202f<a href=\"https:\/\/twitter.com\/richi\" target=\"_blank\" rel=\"nofollow ugc noopener\">@RiCHi<\/a>, <a href=\"https:\/\/threads.net\/@richij\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richij<\/a>, <a href=\"https:\/\/vmst.io\/deck\/@richi\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richi@vmst.io<\/a>, <a href=\"https:\/\/bsky.app\/profile\/richi.bsky.social\" target=\"_blank\" rel=\"nofollow ugc noopener\">@richi.bsky.social<\/a> or <a href=\"mailto:sbbw@richi.co.uk?subject=-sbbw-\">sbbw@richi.uk<\/a>. Ask your doctor before reading. Your mileage may vary. Past per\u00adformance is no guar\u00adantee of future results. Do not stare into laser with re\u00admaining eye. E&amp;OE. 30.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.<\/p>\n","protected":false},"author":8670,"featured_media":2037239,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[590,20983,23406,98344,13571,21858,21028,24367,20984,30691,651,35889,14089,14098,35458,30205,14097,98631,99462,99461,13418,21129,497],"tags":[12626,95381,83533,83517,14064,58786,75349,88301,14105,57759],"class_list":["post-2037237","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security","category-cyberlaw","category-blogs","category-data-privacy","category-data-security","category-sb-featured","category-governance-risk-compliance","category-humor","category-incident-response","category-sb-industry-spotlight","category-iot-ics-security","category-most-read-this-week","category-network-security","category-sb-news","category-popular-post","category-security-awareness","category-sb","category-social-facebook","category-social-linkedin","category-social-x","category-sb-spotlight","category-threats-breaches","category-vulnerabilities","tag-d-link","tag-d-link-corporation","tag-d-link-vulnerability","tag-d-link-zero-day","tag-internet-of-things","tag-internet-of-things-iot","tag-internet-of-things-iot-security","tag-internet-of-things-cyber-security","tag-iot","tag-sb-blogwatch"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.9 (Yoast SEO v23.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed - Security Boulevard<\/title>\n<meta name=\"description\" content=\"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed\" \/>\n<meta property=\"og:description\" content=\"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/\" \/>\n<meta property=\"og:site_name\" content=\"Security Boulevard\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/groups\/24445075146\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/richij\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-21T17:33:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Richi Jennings\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@RiCHi\" \/>\n<meta name=\"twitter:site\" content=\"@securityblvd\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/\",\"url\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/\",\"name\":\"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed - Security Boulevard\",\"isPartOf\":{\"@id\":\"https:\/\/securityboulevard.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png\",\"datePublished\":\"2024-11-21T17:33:40+00:00\",\"dateModified\":\"2024-11-21T17:33:40+00:00\",\"author\":{\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100\"},\"description\":\"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.\",\"breadcrumb\":{\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage\",\"url\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png\",\"contentUrl\":\"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png\",\"width\":770,\"height\":300,\"caption\":\"A D-Link DSR-250N, which is now EOL\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/securityboulevard.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Boulevard (Original)\",\"item\":\"https:\/\/securityboulevard.com\/category\/sb\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"News\",\"item\":\"https:\/\/securityboulevard.com\/category\/sb\/sb-news\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/securityboulevard.com\/#website\",\"url\":\"https:\/\/securityboulevard.com\/\",\"name\":\"Security Boulevard\",\"description\":\"The Home of the Security Bloggers Network\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/securityboulevard.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100\",\"name\":\"Richi Jennings\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/securityboulevard.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g\",\"caption\":\"Richi Jennings\"},\"description\":\"Richi Jennings is a foolish independent industry analyst, editor, and content strategist. A former developer and marketer, he\u2019s also written or edited for Computerworld, Microsoft, Cisco, Micro Focus, HashiCorp, Ferris Research, Osterman Research, Orthogonal Thinking, Native Trust, Elgan Media, Petri, Cyren, Agari, Webroot, HP, HPE, NetApp on Forbes and CIO.com. Bizarrely, his ridiculous work has even won awards from the American Society of Business Publication Editors, ABM\/Jesse H. Neal, and B2B Magazine.\",\"sameAs\":[\"https:\/\/richi.uk\",\"https:\/\/www.facebook.com\/richij\",\"https:\/\/www.linkedin.com\/in\/richi\/\",\"https:\/\/x.com\/RiCHi\",\"https:\/\/www.youtube.com\/c\/richijennings\",\"https:\/\/en.wikipedia.org\/wiki\/User:Richi\"],\"url\":\"https:\/\/securityboulevard.com\/author\/richi\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed - Security Boulevard","description":"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/","og_locale":"en_US","og_type":"article","og_title":"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed","og_description":"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.","og_url":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/","og_site_name":"Security Boulevard","article_publisher":"https:\/\/www.facebook.com\/groups\/24445075146\/","article_author":"https:\/\/www.facebook.com\/richij","article_published_time":"2024-11-21T17:33:40+00:00","og_image":[{"width":770,"height":300,"url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png","type":"image\/png"}],"author":"Richi Jennings","twitter_card":"summary_large_image","twitter_creator":"@RiCHi","twitter_site":"@securityblvd","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/","url":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/","name":"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed - Security Boulevard","isPartOf":{"@id":"https:\/\/securityboulevard.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage"},"image":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage"},"thumbnailUrl":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png","datePublished":"2024-11-21T17:33:40+00:00","dateModified":"2024-11-21T17:33:40+00:00","author":{"@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100"},"description":"D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.","breadcrumb":{"@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#primaryimage","url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png","contentUrl":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png","width":770,"height":300,"caption":"A D-Link DSR-250N, which is now EOL"},{"@type":"BreadcrumbList","@id":"https:\/\/securityboulevard.com\/2024\/11\/d-link-router-critical-rce-sol-richixbw\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securityboulevard.com\/"},{"@type":"ListItem","position":2,"name":"Security Boulevard (Original)","item":"https:\/\/securityboulevard.com\/category\/sb\/"},{"@type":"ListItem","position":3,"name":"News","item":"https:\/\/securityboulevard.com\/category\/sb\/sb-news\/"},{"@type":"ListItem","position":4,"name":"Here\u2019s Yet Another D-Link RCE That Won\u2019t be Fixed"}]},{"@type":"WebSite","@id":"https:\/\/securityboulevard.com\/#website","url":"https:\/\/securityboulevard.com\/","name":"Security Boulevard","description":"The Home of the Security Bloggers Network","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securityboulevard.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/c4ddb2bb099fca608cd9c783bbd00100","name":"Richi Jennings","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securityboulevard.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b26f6b3c4f3ae8b2b257466976990747?s=96&d=mm&r=g","caption":"Richi Jennings"},"description":"Richi Jennings is a foolish independent industry analyst, editor, and content strategist. A former developer and marketer, he\u2019s also written or edited for Computerworld, Microsoft, Cisco, Micro Focus, HashiCorp, Ferris Research, Osterman Research, Orthogonal Thinking, Native Trust, Elgan Media, Petri, Cyren, Agari, Webroot, HP, HPE, NetApp on Forbes and CIO.com. Bizarrely, his ridiculous work has even won awards from the American Society of Business Publication Editors, ABM\/Jesse H. Neal, and B2B Magazine.","sameAs":["https:\/\/richi.uk","https:\/\/www.facebook.com\/richij","https:\/\/www.linkedin.com\/in\/richi\/","https:\/\/x.com\/RiCHi","https:\/\/www.youtube.com\/c\/richijennings","https:\/\/en.wikipedia.org\/wiki\/User:Richi"],"url":"https:\/\/securityboulevard.com\/author\/richi\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/securityboulevard.com\/wp-content\/uploads\/2024\/11\/d-link-eol-rce-0day-richixbw.png","jetpack_shortlink":"https:\/\/wp.me\/p91vu9-8xYF","_links":{"self":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2037237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/users\/8670"}],"replies":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/comments?post=2037237"}],"version-history":[{"count":3,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2037237\/revisions"}],"predecessor-version":[{"id":2037242,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/posts\/2037237\/revisions\/2037242"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/media\/2037239"}],"wp:attachment":[{"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/media?parent=2037237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/categories?post=2037237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityboulevard.com\/wp-json\/wp\/v2\/tags?post=2037237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}