Particle.news

Four Critical Bugs Leave D-Link DIR-878 Exposed as No Patch Is Coming

The long-unsupported model now requires immediate replacement to reduce the risk of remote compromise.

Overview

  • Researchers disclosed four severe flaws in the DIR-878 (CVE-2025-60672, CVE-2025-60673, CVE-2025-60674, CVE-2025-60676) that enable unauthenticated remote code execution.
  • D-Link will not release fixes because the router has been End-of-Life since January 2021, and the company advises owners to replace the device.
  • The attack can be carried out remotely with specially crafted HTTP requests and does not require login credentials or physical proximity.
  • A successful compromise can expose Wi-Fi traffic and facilitate malware distribution to devices on the local network.
  • Active exploitation has not been confirmed, but disclosure increases risk, and the FBI cautions that unsupported routers commonly remain unpatched and should be retired.