Overview
The (non-US) DI-7001 product family, including applicable derivative models, hardware revisions, and firmware versions, has reached End-of-Life (EOL) / End-of-Service Life (EOS) status.
D-Link Corporation and D-Link North America (D-Link Systems, Inc.) recommend that current users take one or more of the following actions:
1. Transition to a current-generation product.
2. Perform a comprehensive backup of any configuration or other data that should be retained.
3. Contact the appropriate regional D-Link office for additional recommendations or product information: D-Link Regional Offices
Consistent with standard industry lifecycle practices, products that have reached EOL/EOS status may no longer receive technical support, firmware updates, security updates, or further product development.
Please review the reported vulnerability information and recommendations below.
Third-Party Report Information
Report 1 - Off-Path DNS Cache Poisoning
Product: DI-7001
Reported Firmware: v17.01.11A1
Discovered: January 2, 2025
Research Organization: AOSP Lab, Nankai University
Author: Xiang Li / OSP Lab, Nankai University
Contact: idealeer521 _at_ gmail _dot_ com
Details:
A third-party researcher reported that a DI-7001 device operating firmware version 17.01.11A1 may be susceptible to an off-path DNS cache-poisoning attack, potentially allowing an attacker to inject unauthorized DNS information for a targeted domain.
Report 2 - Command Execution Vulnerability
CVE: CVE-2025-26237
Product Identified in CVE Record: D-Link DI-7001 MINI_5G
Reported Firmware: 19.10.31A1
CVE Published: August 24, 2026
CVE Record: CVE-2025-26237
Details:
The published CVE record identifies a code-execution vulnerability affecting D-Link DI-7001 MINI_5G firmware version 19.10.31A1. The reported vulnerability involves improper handling of the flag parameter associated with the msp_info function. According to the CVE record, exploitation of the reported condition may allow arbitrary commands to be executed.
The CVE record identifies this vulnerability as CVE-2025-26237.
Affected / EOL Models
|
Model
|
Region
|
Hardware Revision
|
End of Support
|
Legacy Website
|
Last Updated
|
|
DI-7001 Product Family
|
Worldwide
|
All applicable Series Models & Hardware Revisions
|
02/10/2021
|
No (non-US)
|
08/31/2026
|
Note: The specific public CVE record for CVE-2025-26237 identifies DI-7001 MINI_5G firmware version 19.10.31A1. The broader model and revision information shown above reflects the EOL/EOS lifecycle status of the DI-7001 product family and should not be interpreted as an assertion that every model, hardware revision, or firmware version is affected by CVE-2025-26237.
Recommendation for EOL / EOS Products
As part of normal product lifecycle management, D-Link may determine that certain products have reached a stage where continued support or development is no longer available. Such determinations may result from factors including technology evolution, changes in market requirements, product innovation, component availability, product efficiency, or replacement by newer products offering improved functionality.
Products that have reached EOL/EOS status may no longer receive firmware development, security updates, technical support, or other maintenance releases.
D-Link recommends that customers using affected EOL/EOS products transition to current-generation products that remain within an active support lifecycle.
For US Consumers
The DI-7001 products discussed in this announcement are non-US products.
For products that have reached EOL/EOS status, further firmware development, security updates, or extended technical support may no longer be available.
Because development and support for these products have ended, D-Link Systems, Inc. may not be able to provide corrective firmware for vulnerabilities subsequently reported against these devices.
Users located outside the United States should contact their appropriate regional D-Link office for product-specific assistance and replacement information: D-Link Regional Offices
D-Link recommends retiring EOL/EOS products and transitioning to currently supported products.
For users who continue operating an EOL/EOS device during a transition period, D-Link recommends using the latest firmware previously made available for the exact model and hardware revision, where such firmware remains available. Users should also maintain unique administrative credentials and enable available wireless encryption using strong, unique passwords.
Regarding Firmware for EOL / EOS Devices
Firmware updates are an important mechanism for addressing vulnerabilities in supported products. However, products that have reached EOL/EOS status may no longer receive new firmware or security updates.
If firmware remains available for an EOL/EOS product, users should verify that:
· The firmware is intended for the exact product model and hardware revision.
· The firmware was obtained from an authorized D-Link source.
· The update completed successfully.
· The firmware version displayed in the device's management interface corresponds to the version that was installed.
D-Link products may have multiple hardware revisions, and firmware intended for one hardware revision may not be appropriate for another. The hardware revision is typically identified on the product label near the serial number and may also be displayed within the device's management interface.
Where no supported firmware update is available for an EOL/EOS device, D-Link recommends transitioning to a current-generation product that remains within an active support lifecycle.