Overview
- Researchers disclosed four severe flaws in the DIR-878 (CVE-2025-60672, CVE-2025-60673, CVE-2025-60674, CVE-2025-60676) that enable unauthenticated remote code execution.
- D-Link will not release fixes because the router has been End-of-Life since January 2021, and the company advises owners to replace the device.
- The attack can be carried out remotely with specially crafted HTTP requests and does not require login credentials or physical proximity.
- A successful compromise can expose Wi-Fi traffic and facilitate malware distribution to devices on the local network.
- Active exploitation has not been confirmed, but disclosure increases risk, and the FBI cautions that unsupported routers commonly remain unpatched and should be retired.