Major D-Link security flaw - Check if your router is affected

Yeah... My afrihost supplied router updated to a special non-website-available Russian firmware and this was afrihosts reply to me:
"The reason it updates from D-link Russia is that that is where we get the routers from and as such the firmware updates from there as well. We also have access to firmware version 3.0.5 because we requested a later firmware version from D-link due to issues on 3.0.4."

This was after i had wifi connectivity issues and was investigating myself. I know of at-least 2 other people in the area with the same problem, same router, also from afrihost.

I now have a wonderful tp-link archer router :)
 
I have the 'safe' DIR-825 from Afrihost, but it's only being used as a switch and 5GHz Wi-Fi booster. The real router for the home network is the UniFi Security Gateway and the firmware is up to date. Should be secure enough.

:ROFL: In which world?
 
:ROFL: In which world?

It has security in its name. It is therefore secure.

giphy.gif
 
The real router for the home network is the UniFi Security Gateway and the firmware is up to date. Should be secure enough.

Nice. This is the exact reason I dropped Tplink in favour of something like Mikrotik. You get regular updates. Pretty sure there are security holes in many more consumer routers because they never get updates, but these things are just never announced.
 
Nice. This is the exact reason I dropped Tplink in favour of something like Mikrotik. You get regular updates. Pretty sure there are security holes in many more consumer routers because they never get updates, but these things are just never announced.

Then you should move away from Mikrotik to a real firewall like Sonicwall, Fortigate etc.
 
Nice. This is the exact reason I dropped Tplink in favour of something like Mikrotik. You get regular updates. Pretty sure there are security holes in many more consumer routers because they never get updates, but these things are just never announced.
They are announced, by researchers, only a few months later (because they are typically bound by responsible disclosure ethics). By then it's far too late. The same goes for major commercial firewall vendors, but at least they are rigorously tested and have to fix vulnerabilities within a specific timeframe in order to retain ICSA and NSS Labs certification.

If it runs code, it is vulnerable. Best to disable any untrusted inbound connections.
 
"Consequently, the only solution to secure your network if your device is affected by this vulnerability is to replace your router with a newer model."

A good time to move away from a manufacturer that does not support its own products.
Would you have bought TP-link in the first place if you expected to be dropped?
 
"Consequently, the only solution to secure your network if your device is affected by this vulnerability is to replace your router with a newer model."

A good time to move away from a manufacturer that does not support its own products.
Would you have bought TP-link in the first place if you expected to be dropped?
Why not just flash open wrt?
 
having any vulnerable router is generally a bad idea, but this article reminded me about this little router, also d-link, which i still see in so many places, which has been unpatched for YEARS and people still use themView attachment 737919

dsl-2750u
Hahaha I've still got 4x of these sitting in a cupboard at home. They were great about 5yrs ago. I only changed mine out about 6months ago for a Mikrotik hAP Lite.
 
I received this error message after a few failed attempts at logging into my D-link DIR-825 after receiving DNS-related delays and errors on Vumatel this afternoon.

Is this message evidence that the router is sending my login details to .CN ?



1586432199030.png
 
Last edited:
I received this error message after a failed attempts at logging into my D-link DIR-825 after receiving DNS-related delays and errors on Vumatel this afternoon.

Is this message evidence that the router is sending my login details to .CN ?



View attachment 815407
I receive the same message while navigating around the management server (randomly) using Chrome. Does not happen when using Edge.

1586761311143.png
 
Top
Sign up to the MyBroadband newsletter
X