D-Link says it is not fixing four RCE flaws in DIR-846W routers
ID: 677165bd-fbad-5d92-ae8b-1abca50ce29d
STIX ID: report--677165bd-fbad-5d92-ae8b-1abca50ce29d
Feed Name: Bleeping Computer
D‑Link DIR‑846W routers are affected by four remote code execution vulnerabilities (three CVSS 9.8 critical, one CVSS 8.8) disclosed by a researcher; D‑Link confirmed the issues but will not provide patches due to the product reaching end-of‑support, advising retirement or mitigation (latest firmware, strong admin passwords, Wi‑Fi encryption). Although the researcher withheld PoC exploits, published details and the device's continued use globally — combined with historical exploitation of D‑Link flaws by Mirai/Moobot botnets — create a high risk that these routers could be weaponized for DDoS or further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
