Skip to main content
  1. Home
  2. Computing
  3. News

Despite serious security flaws, D-Link will (again) not patch some routers

Add as a preferred source on Google
Piotr Adamowicz

For the second time in roughly a year, D-Link has failed to act on warnings from security researchers involving the company’s routers. The latest incident arose after Silesian University of Technology researcher Błazej Adamczyk contacted D-Link last May about three vulnerabilities affecting eight router models. Following the warning, D-Link patched two of the affected routers, but did not initially reveal how it would proceed for the remaining six models. After further prompting from Adamczyk, D-Link revealed that the remaining six routers would not get a security patch because they were considered end-of-life models, leaving affected owners out in the cold.

“The D-Link models affected are the DWR-116, DWR-140L, DWR-512, DWR-640L, DWR-712, DWR-912, DWR-921, and DWR-111, six of which date from 2013, with the DIR-640L first appearing in 2012 and the DWR-111 in 2014,” Naked Security reported. Though these are not current models in D-Link’s portfolio, many of the listed models are still likely to be in use.

Recommended Videos

As a result of this impasse, Adamczyk released details about the security flaws, following responsible security protocols after giving D-Link notice and the opportunity to address the issues. Of significance is that this is the second time in about a year that D-Link has failed to address security vulnerabilities affecting its products after being notified by researchers; the last time this happened was in 2017 and involved a different set of vulnerabilities.

Adamczyk published a video showing how the vulnerabilities could be used together to achieve a path traversal attack on the affected routers. The security researcher noted that the new flaw arose after D-Link reported that it had fixed a prior security flaw. Also known as “directory traversal” or “dot dot slash” attacks, these flaws allow a malicious attacker to gain access to system files with a simple HTTP request.

Despite D-Link’s spotty history with supporting older router models, the manufacturer is not alone in leaving routers unpatched. The American Consumer Institute reported that of the 186 routers it had tested, 155 contained firmware vulnerabilities. In total, ACI discovered more than 32,000 known vulnerabilities in its study. “Our analysis shows that, on average, routers contained 12 critical vulnerabilities and 36 high-risk vulnerabilities, across the entire sample,” ACI noted in its report. “The most common vulnerabilities were medium-risk, with an average of 103 vulnerabilities per router.”

For shoppers who are in the market for a new router, it’s probably best to also check with the manufacturer to see what the supported lifespan of the router is. If the router is nearing its end of life, as in the case illustrated here, you may not get patches, regardless of how serious a security vulnerability may be. If you have an older router, you may want to consider checking out our guide for the best router options before you decide to upgrade.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more
Before You Pay More for DDR5, Think About How Much Memory You Need
The MSI Cubi 5 1MA makes a strong case for looking beyond the newest specs
MSI Cubi 5 1MA compact mini PC with Intel Core processor

There is an easy trap to fall into when buying a new PC. The newer specification usually sounds like the better one, so choosing DDR5 memory over DDR4 can seem like an obvious upgrade. But with memory prices climbing to unusually high levels, it is worth asking whether you will actually benefit from paying more for that extra speed.

For many people buying a PC primarily for work, the answer comes down to how they use it. Everyday tasks such as browsing, email, spreadsheets, presentations, and video calls generally do not need the extremely high memory bandwidth DDR5 offers. Having enough RAM to keep several of those tasks running comfortably can be far more relevant.

Read more
Adobe Acrobat’s latest update could make working with PDFs considerably easier
New Acrobat features make it easier to understand, refine and present information in PDFs
Page, Text, Clapperboard

This post is brought to you in paid partnership with Adobe

PDFs remain one of those unavoidable parts of working life. Reports, research papers, presentations, proposals, financial documents and client material still tend to arrive as PDFs, and the real problem is rarely opening or reading them. It is dealing with everything that comes after: finding the useful information in a lengthy document, understanding it quickly and eventually turning it into something presentable.

Read more