endoflife.ai
End of Support EOS Edge Device List EOL Checker EOL Watch

Exploited, Abandoned, Still Online: The End-of-Life Routers CISA Keeps Ordering Unplugged

By Scott Bissett  ·  Published: September 2, 2026  ·  EOL Watch — news analysis  ·  Every date verified against D-Link's support announcements (SAP10371, SAP10264, SAP10358), Zyxel's advisory, and CISA's KEV catalog — methodology

Most entries in CISA's Known Exploited Vulnerabilities catalog tell federal agencies to patch by a due date. Seven of them tell agencies something else: unplug the device. The required action on CVE-2021-45382, covering five D-Link router models, reads in full: "The impacted product is end-of-life and should be disconnected if still in use." There is no patch to apply, and there never will be — the affected models reached end of support in 2017 and 2018, per D-Link's own advisory, four years before the exploitation that put them in the catalog.

These disconnect entries are the clearest official record anywhere of a pattern this site exists to track: a product's end-of-support date is a security event, and its consequences arrive on the attacker's schedule, not the vendor's. The gap between "vendor stopped patching" and "CISA confirmed active exploitation" runs as long as seven years in this set — and it is still widening, because two of the seven entries were added in 2025.

The disconnect list

Every row is verified against the vendor's advisory and CISA's KEV catalog. "Vendor end of support" is the date printed in the vendor's own affected-models table.

KEV entryDevice(s)Vendor end of supportAdded to KEVCISA's required action
CVE-2021-45382D-Link DIR-810L / 820L / 826L / 830L / 836LNov 1, 2017 – Feb 28, 2018Apr 4, 2022"end-of-life and should be disconnected if still in use"
CVE-2022-26258D-Link DIR-820LNov 1, 2017Sep 8, 2022"end-of-life and should be disconnected if still in use"
CVE-2019-17621D-Link DIR-859Dec 10, 2020Jun 29, 2023"apply updates … or discontinue use … if updates are unavailable"
CVE-2023-25280D-Link DIR-820LNov 1, 2017Sep 30, 2024"end-of-life (EoL) and/or end-of-service (EoS) … discontinue utilization"
CVE-2024-0769D-Link DIR-859Dec 10, 2020Jun 25, 2025"discontinue use of the product if mitigations are unavailable"
CVE-2024-40890 & CVE-2024-40891Zyxel legacy DSL CPE (VMG1312/3312/3313/3926/4325/4380/8324/8924, SBG3300/3500)"end-of-life (EOL) for years" — ZyxelFeb 11, 2025"could be end-of-life … discontinue product utilization if a current mitigation is unavailable"
The arithmetic worth sitting with: the DIR-820L's end-of-support date is November 1, 2017. CVE-2023-25280 entered the KEV catalog on September 30, 2024 — almost seven years later. The DIR-859 was abandoned December 10, 2020; CVE-2024-0769 was added June 25, 2025 — four and a half years after end of support, for a flaw that was itself only disclosed years after the last patch shipped. Nobody was ever going to fix it. The CVE record for the Zyxel pair carries the label security databases reserve for exactly this situation: "UNSUPPORTED WHEN ASSIGNED."

What the vendors themselves say

None of this is contested by the vendors — their advisories are unusually blunt, which is what makes them quotable primary sources.

D-Link, in SAP10358 (the advisory CISA's own KEV entry links for CVE-2023-25280): end-of-life products "no longer receive device software updates and security patches and are no longer supported." Its standing recommendation, repeated across SAP10371 and SAP10264, is that EOL devices "be retired and replaced," with a caution that continued use "may be a risk to devices connected to it." And the detail that says more than any prose: the Fixed Firmware column in D-Link's own affected-model table reads "Not Available" on every row — DIR-626L, DIR-636L, DIR-808L, DIR-810L, DIR-820L, DIR-826L. The vendor publishes the vulnerability list and the empty fix column side by side.

Zyxel, in its February 2025 advisory for the exploited DSL gateway flaws: the affected models "are legacy products that have reached end-of-life (EOL) for years," and users should "replace them with newer-generation products for optimal protection." The exploitation that triggered the advisory was reported publicly by researchers observing live attack traffic — Zyxel's response was not a patch but a replacement recommendation, because for hardware that far past end of life there is nothing else to ship.

Why "disconnect" is the whole federal remedy

Under Binding Operational Directive 22-01, every KEV entry carries a mandatory remediation action and due date for US federal civilian agencies. For supported software, that means patching. For these devices, CISA's catalog language has evolved into an explicit end-of-life doctrine — from "should be disconnected if still in use" (2022) to "Users should discontinue utilization of the product" (2024–2025). When the vendor's fix column reads "Not Available," removal is the remediation.

Enterprise edge devices got a whole directive about this problem in 2026: BOD 26-02 orders agencies to inventory and decommission end-of-support firewalls, VPN gateways, and routers on a twelve-month clock — the population our EOS Edge Device List tracks. But the consumer and small-office tier below that — the DIR-859s and DSL gateways of the world — has no directive, no inventory requirement, and no decommission deadline. The KEV disconnect entries are the only standing federal signal that this hardware is actively dangerous, and they arrive one exploited CVE at a time, years after the vendor walked away.

Who actually holds this risk: not primarily federal agencies — small offices, branch sites, home-office workers, and the ISPs that shipped these gateways to subscribers. An end-of-life router doesn't announce itself: it keeps routing packets exactly as well as the day support ended, while its unpatched services face the internet. The devices in this table are precisely the class that gets conscripted into botnets and used as beachheads — which is how their CVEs earned KEV entries in the first place: someone observed exploitation in the wild.

What to do with this list

If you run any device on this page, the vendors and CISA agree on the remediation: replace it. There is no configuration that makes an unpatchable, actively-exploited device safe to keep on the internet. Beyond the specific models: treat vendor end-of-support dates as removal deadlines for anything that faces the network — the same discipline BOD 26-02 now enforces on federal edge fleets, applied one tier down. Our end-of-support hub explains the vocabulary, the EOS Edge Device List tracks the enterprise edge platforms with the same verified-at-the-vendor rigor as this article, and the Exploited & Unpatchable feed documents the cases where KEV-listed exploitation and end-of-life status collide with no fix on the affected line.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

A note on what's not in this article

We verified two adjacent cases and left them out, because the evidence pointed the other way. DrayTek routers appear in the KEV catalog too — but DrayTek shipped firmware fixes for its listed CVEs, including on aging models, so it does not belong on an abandoned-hardware list. And WatchGuard's Firebox — whose T35-class models reached end of life on December 31, 2025 with two KEV entries close behind — published fixed builds specifically for those models, which disqualifies it from the no-patch pattern this article documents. That is the test every row above passed: the vendor's own advisory confirms no fix exists and none is coming.

Frequently Asked Questions

Which end-of-life routers are in CISA's KEV catalog?

Seven entries cover exploited flaws in vendor-abandoned devices: five against D-Link routers — CVE-2021-45382 (DIR-810L/820L/826L/830L/836L), CVE-2022-26258 and CVE-2023-25280 (DIR-820L), CVE-2019-17621 and CVE-2024-0769 (DIR-859) — and two against Zyxel legacy DSL gateways (CVE-2024-40890/40891). The D-Link models reached end of support between November 2017 and December 2020 per D-Link's own advisories; Zyxel says its affected models have been EOL "for years."

What does CISA tell agencies to do about these devices?

Disconnect them. Where most KEV entries require a patch by a due date, these read "The impacted product is end-of-life and should be disconnected if still in use" or "Users should discontinue utilization of the product." Under BOD 22-01 every KEV entry carries a mandatory remediation — and for a device that will never see another patch, the only remediation is removal.

How long after end of life do these devices keep getting exploited?

Up to seven years and counting in this set. DIR-820L: end of support November 1, 2017, KEV entry September 30, 2024. DIR-859: end of support December 10, 2020, KEV entry June 25, 2025 — for a vulnerability disclosed years after the last patch shipped. Exploitation does not wind down after end of support; the target just stops moving.

Will D-Link or Zyxel patch these vulnerabilities?

No. D-Link states EOL products "no longer receive device software updates and security patches," and the Fixed Firmware column in its own advisory table reads "Not Available" for every affected model; its recommendation is that the devices "be retired and replaced." Zyxel recommends replacing its affected DSL gateways with newer-generation products. Replacement is the fix.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)