• Home Support Forums Security Advisories Shop     English | French
Support Announcement
DIR-803, DIR-815, DIR-816L, DIR-860L, DIR-645, DIR-865L :: End of Support Devices : Recent Security Vulnerability Report

Overview

 

The DIR-803, DIR-815, DIR-816L, DIR-860L, DIR-645, DIR-865L all hardware revisions, have reached End of Support ("EOS") / End of Life ("EOL") of there Lifecycles.


As a  general policy, when products reach EOS/EOL, they can no longer be supported, and all firmware development for the products ceases. Products  purchased in the US that have reached EOS/EOL are moved to our Legacy Products site (legacy.us.dlink.com) which is the final archive as of the EOS/EOL date. Please read information and recommendations below.

 

Known Security-Related Issues after EOS/EOL date

 

sek1th :: sh1071@live.cn :: 08/30/2020 :: Link to Report

 

Reported Models with Proof of Concept ("PoC"):

DIR-803 - Hardware Revision Ax - F/W 1.04.B02  :  Reflected Cross-site scripting  ("XSS") vulnerability

DIR-816L - Hardware Revision B1 - F/W 2.06 & 2.06.B09_BETA :  Reflected Cross-site scripting ("XSS") vulnerability

 

Reported Models without PoC:
DIR-645 - Hardware Revision Ax - F/W v1.06B01

DIR-815 - Hardware Revision Bx- F/W 2.07.B01

DIR-860L - Hardware Revision Ax - F/W 1.10B04

DIR-865L - Hardware Revision Ax - F/W 1.08B01

 

Status of D-Link Models

 

Model Region Hardware Revision Last Sales Date End of Support Legacy Website
DIR-645 Globally A1/B1 n/a 07/14/14 n/a
DIR-645 Only USA A1 05/01/18 12/31/18 Click Here
DIR-803 Globally A1/B1/B2
n/a 03/01/16
n/a
DIR-803 Only USA A1 11/18/14 03/01/20
Click Here
DIR-815 Globally

A1/B1/C1

n/a

12/01/15

n/a
DIR-815 Only USA A1/B1 02/18/15 12/29/17 Click Here
DIR-816L Globally  A1/B1/C1 n/a 06/30/16
n/a
DIR-816L Only USA  B1 04/07/16 12/15/19 Click Here
DIR-860L Globally  A1/B1  n/a 08/08/16  n/a
DIR-860L Only USA  A1/B1   09/13/18 08/07/20  Click Here
DIR-865L Globally  A1 n/a

09/02/14

n/a
DIR-865L Only USA  A1

 12/07/16

02/01/16  Click Here

 

Recommendation for End of Support /End of Life Products


From time to time, D-Link will decide that some of its products have reached End of Support ("EOS") / End of Life (“EOL”). D-Link may choose to EOS/EOL a product due to evolution of technology, market demands,  new innovations, product efficiencies based on new technologies, or the product matures over time and should be replaced by functionally superior technology.

 

For US Consumer


If a product has reached End of Support ("EOS") / End of Life ("EOL"), there is normally no further extended support or development for it. Once a product reaches its EOL/EOS date, it is transferred to https://legacy.us.dlink.com/ .

 

Typically for these products, D-Link will be unable to resolve device or firmware issues since all development and customer support has ceased. 

 

D-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it. If US consumers continue to use these devices against D-Link's recommendation, please make sure the device has the most recent firmware from https://legacy.us.dlink.com/ installed, make sure you frequently update the device's unique password to access its web-configuration, and always have WIFI encryption enabled with a unique password.