Dangerous security flaw found in six D-Link routers — stop using these right now
The company is offering 20% off new routers for impacted customers
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
This week D-Link identified six older VPN router models, released in 2011 and 2012, which contain a critical security flaw that could cause them to become infected with malware.
Since the models are all older and at the end of their service life, D-Link will not be issuing a patch or a fix – and full details about the flaw are also not available as this vulnerability is likely able to be exploited.
However, what we know from the bug report is that the flaw could allow unauthorized users to conduct a remote code execution attack; essentially a memory problem within the router could result in a hacker or other threat actor injecting malware or other malicious code into the device.
D-Link is offering affected customers 20% off the purchase of a newer model router, the D-Link DSR-250v2 4-Port Unified Services VPN Router, which retails at $210 on D-Link’s website. It can be found cheaper on Amazon right now because of Black Friday sales.
If you're looking to change brands though (which you might be after a security incident like this one), take a look at our roundup of the best Wi-Fi routers. Likewise, if you want the latest and greatest wireless tech, there are some fantastic Black Friday Wi-Fi 7 router deals on both traditional routers and mesh ones too.
D-Link’s report states if you continue to use the affected devices, you do so against the company’s recommendations; however you should be sure to update the firmware, frequently update the password and keep Wi-Fi encrypted with a separate password.
Vulnerable D-Link routers
- DSR-150 (support ended May 2024)
- DSR-150N (support ended May 2024)
- DSR-250 (support ended May 2024)
- DSR-250N (support ended May 2024)
- DSR-500N (support ended September 2015)
- DSR-1000N (support ended September 2015)
PCMag points out that some of these devices are still on sale at Amazon, so when purchasing tech devices always check their release dates and be sure to do plenty of research on the device itself. Read background information on what a VPN router is, what the pros and cons are and read reviews before making a purchase.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
More from Tom's Guide
- ExpressVPN steps up its game with new Credit Scanner tool
- Is VPN by Google coming to Pixel Tablet?
- Microsoft is changing the way admin privileges work in Windows - here's why

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps.










