Story perspectives
D-Link Warns of Critical Vulnerabilities in Outdated Routers
11/22/2025
1 of 1
Story summary
- D-Link disclosed four remote code execution vulnerabilities in its DIR-878 routers (discontinued in 2021), tracked as CVE-2025-60672 to CVE-2025-60676 with severities 6.5–6.8.
- A security researcher released proof-of-concept exploit code, raising concerns about potential real-world attacks.
- These routers can still be purchased and are often targeted by botnets like Mirai.
- D-Link recommends replacing outdated hardware or updating firmware and using strong, frequently changed passwords.
