Retire it rather than fix it — the instruction for D-Link routers past their life
For the information disclosure flaw in the D-Link DIR-605 router, CISA called not for a fix but for the equipment to be retired and replaced, because every associated hardware revision had reached end of life or end of service.
Key facts
- CVE IDCVE-2021-40655
- Affected (vendor / product)D-Link DIR-605 Router
- CWECWE-863
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2024-06-06 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2021-40655 is an information disclosure vulnerability in D-Link DIR-605 routers.
- A forged post request aimed at the /getcfg.php page will yield up a username and a password.
- The required action is that the equipment be retired and something else put in its place, following the vendor.
- The instruction gives its reason: these are legacy products and all associated hardware revisions have reached end of life or end of service.
- Listed 16 May 2024 with a due date of 6 June, a window of twenty-one days; among the 1,579 entries without an article this site holds as of 2026-09-05, four share this exact wording.
1No fix among the options
The six entries so far all asked, to varying degrees, for something to be fixed. This one does not. What it asks for is the equipment to be retired and replaced. Repair does not appear as an option.
2The reason is written into the instruction
Finding a reason in the required action field is itself unusual. Most entries write only what to do. Here the case for why an update is not the answer comes first, and the conclusion follows it.
3Few instructions rest on end of life
Instructions calling for replacement on grounds of end of life number 64 as a family. This exact wording, though, appears on four. It belongs to the individually written side.
4When there is no longer anyone to fix it
A vulnerability can be fixed for as long as the product lives. Once the product's life ends, the party that would fix it is gone. What remains is a choice between continuing to use it and replacing it.
The window was twenty-one days, listed 16 May 2024 and due 6 June. Replacement costs more time and money than a fix, yet the window stays at the most common twenty-one. The next article closes the series with an entry where the vendor instructions themselves did not exist.
Why it matters
A vulnerability remains fixable for as long as the product lives; once its life ends, the party that would fix it no longer exists. The instruction then cannot ask for an update and asks for retirement and replacement instead. That a reason appears in the required action field at all is exceptional, and shows the case for not updating had to be made first.
FAQ
Why replace rather than update?
What kind of flaw is it?
Is this the same as discontinuing use?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).