• Home Support Forums Security Advisories Shop     English | French
Security Announcement
Announcement > SAP10425
(Non-US) DI-7001 / DI-7001 Mini-Versions:: All H/W Versions / All Firmware Versions : End-of-Life / End-of-Service : Reported Vulnerabilities
Publication ID: SAP10425
Resolved Status: Yes
Published on: 18 March 2025 9:54 GMT
Last updated on: 1 September 2026 2:07 GMT

 

Overview

 

The (non-US) DI-7001 product family, including applicable derivative models, hardware revisions, and firmware versions, has reached End-of-Life (EOL) / End-of-Service Life (EOS) status.

 

D-Link Corporation and D-Link North America (D-Link Systems, Inc.) recommend that current users take one or more of the following actions:

 

1.     Transition to a current-generation product.

2.     Perform a comprehensive backup of any configuration or other data that should be retained.

3.     Contact the appropriate regional D-Link office for additional recommendations or product information: D-Link Regional Offices

 

Consistent with standard industry lifecycle practices, products that have reached EOL/EOS status may no longer receive technical support, firmware updates, security updates, or further product development.

 

Please review the reported vulnerability information and recommendations below.

 

Third-Party Report Information

 

Report 1 - Off-Path DNS Cache Poisoning

Product: DI-7001

Reported Firmware: v17.01.11A1

Discovered: January 2, 2025

Research Organization: AOSP Lab, Nankai University

Author: Xiang Li / OSP Lab, Nankai University

Contact: idealeer521 _at_ gmail _dot_ com

 

Details:

A third-party researcher reported that a DI-7001 device operating firmware version 17.01.11A1 may be susceptible to an off-path DNS cache-poisoning attack, potentially allowing an attacker to inject unauthorized DNS information for a targeted domain.

 

Report 2 - Command Execution Vulnerability

 

CVE: CVE-2025-26237

Product Identified in CVE Record: D-Link DI-7001 MINI_5G

Reported Firmware: 19.10.31A1

CVE Published: August 24, 2026

CVE Record: CVE-2025-26237

 

Details:

The published CVE record identifies a code-execution vulnerability affecting D-Link DI-7001 MINI_5G firmware version 19.10.31A1. The reported vulnerability involves improper handling of the flag parameter associated with the msp_info function. According to the CVE record, exploitation of the reported condition may allow arbitrary commands to be executed.

The CVE record identifies this vulnerability as CVE-2025-26237.

 

Affected / EOL Models

 

Model

Region

Hardware Revision

End of Support

Legacy Website

Last Updated

DI-7001 Product Family

Worldwide

All applicable Series Models & Hardware Revisions

02/10/2021

No (non-US)

08/31/2026

 

Note: The specific public CVE record for CVE-2025-26237 identifies DI-7001 MINI_5G firmware version 19.10.31A1. The broader model and revision information shown above reflects the EOL/EOS lifecycle status of the DI-7001 product family and should not be interpreted as an assertion that every model, hardware revision, or firmware version is affected by CVE-2025-26237.

 

Recommendation for EOL / EOS Products

 

As part of normal product lifecycle management, D-Link may determine that certain products have reached a stage where continued support or development is no longer available. Such determinations may result from factors including technology evolution, changes in market requirements, product innovation, component availability, product efficiency, or replacement by newer products offering improved functionality.

 

Products that have reached EOL/EOS status may no longer receive firmware development, security updates, technical support, or other maintenance releases.

 

D-Link recommends that customers using affected EOL/EOS products transition to current-generation products that remain within an active support lifecycle.

 

For US Consumers

 

The DI-7001 products discussed in this announcement are non-US products.

 

For products that have reached EOL/EOS status, further firmware development, security updates, or extended technical support may no longer be available.

 

Because development and support for these products have ended, D-Link Systems, Inc. may not be able to provide corrective firmware for vulnerabilities subsequently reported against these devices.

 

Users located outside the United States should contact their appropriate regional D-Link office for product-specific assistance and replacement information: D-Link Regional Offices

 

D-Link recommends retiring EOL/EOS products and transitioning to currently supported products.

 

For users who continue operating an EOL/EOS device during a transition period, D-Link recommends using the latest firmware previously made available for the exact model and hardware revision, where such firmware remains available. Users should also maintain unique administrative credentials and enable available wireless encryption using strong, unique passwords.

 

Regarding Firmware for EOL / EOS Devices

 

Firmware updates are an important mechanism for addressing vulnerabilities in supported products. However, products that have reached EOL/EOS status may no longer receive new firmware or security updates.

 

If firmware remains available for an EOL/EOS product, users should verify that:

 

·       The firmware is intended for the exact product model and hardware revision.

·       The firmware was obtained from an authorized D-Link source.

·       The update completed successfully.

·       The firmware version displayed in the device's management interface corresponds to the version that was installed.

 

D-Link products may have multiple hardware revisions, and firmware intended for one hardware revision may not be appropriate for another. The hardware revision is typically identified on the product label near the serial number and may also be displayed within the device's management interface.

 

Where no supported firmware update is available for an EOL/EOS device, D-Link recommends transitioning to a current-generation product that remains within an active support lifecycle.