Exploited, Abandoned, Still Online: The End-of-Life Routers CISA Keeps Ordering Unplugged
Most entries in CISA's Known Exploited Vulnerabilities catalog tell federal agencies to patch by a due date. Seven of them tell agencies something else: unplug the device. The required action on CVE-2021-45382, covering five D-Link router models, reads in full: "The impacted product is end-of-life and should be disconnected if still in use." There is no patch to apply, and there never will be — the affected models reached end of support in 2017 and 2018, per D-Link's own advisory, four years before the exploitation that put them in the catalog.
These disconnect entries are the clearest official record anywhere of a pattern this site exists to track: a product's end-of-support date is a security event, and its consequences arrive on the attacker's schedule, not the vendor's. The gap between "vendor stopped patching" and "CISA confirmed active exploitation" runs as long as seven years in this set — and it is still widening, because two of the seven entries were added in 2025.
The disconnect list
Every row is verified against the vendor's advisory and CISA's KEV catalog. "Vendor end of support" is the date printed in the vendor's own affected-models table.
| KEV entry | Device(s) | Vendor end of support | Added to KEV | CISA's required action |
|---|---|---|---|---|
| CVE-2021-45382 | D-Link DIR-810L / 820L / 826L / 830L / 836L | Nov 1, 2017 – Feb 28, 2018 | Apr 4, 2022 | "end-of-life and should be disconnected if still in use" |
| CVE-2022-26258 | D-Link DIR-820L | Nov 1, 2017 | Sep 8, 2022 | "end-of-life and should be disconnected if still in use" |
| CVE-2019-17621 | D-Link DIR-859 | Dec 10, 2020 | Jun 29, 2023 | "apply updates … or discontinue use … if updates are unavailable" |
| CVE-2023-25280 | D-Link DIR-820L | Nov 1, 2017 | Sep 30, 2024 | "end-of-life (EoL) and/or end-of-service (EoS) … discontinue utilization" |
| CVE-2024-0769 | D-Link DIR-859 | Dec 10, 2020 | Jun 25, 2025 | "discontinue use of the product if mitigations are unavailable" |
| CVE-2024-40890 & CVE-2024-40891 | Zyxel legacy DSL CPE (VMG1312/3312/3313/3926/4325/4380/8324/8924, SBG3300/3500) | "end-of-life (EOL) for years" — Zyxel | Feb 11, 2025 | "could be end-of-life … discontinue product utilization if a current mitigation is unavailable" |
What the vendors themselves say
None of this is contested by the vendors — their advisories are unusually blunt, which is what makes them quotable primary sources.
D-Link, in SAP10358 (the advisory CISA's own KEV entry links for CVE-2023-25280): end-of-life products "no longer receive device software updates and security patches and are no longer supported." Its standing recommendation, repeated across SAP10371 and SAP10264, is that EOL devices "be retired and replaced," with a caution that continued use "may be a risk to devices connected to it." And the detail that says more than any prose: the Fixed Firmware column in D-Link's own affected-model table reads "Not Available" on every row — DIR-626L, DIR-636L, DIR-808L, DIR-810L, DIR-820L, DIR-826L. The vendor publishes the vulnerability list and the empty fix column side by side.
Zyxel, in its February 2025 advisory for the exploited DSL gateway flaws: the affected models "are legacy products that have reached end-of-life (EOL) for years," and users should "replace them with newer-generation products for optimal protection." The exploitation that triggered the advisory was reported publicly by researchers observing live attack traffic — Zyxel's response was not a patch but a replacement recommendation, because for hardware that far past end of life there is nothing else to ship.
Why "disconnect" is the whole federal remedy
Under Binding Operational Directive 22-01, every KEV entry carries a mandatory remediation action and due date for US federal civilian agencies. For supported software, that means patching. For these devices, CISA's catalog language has evolved into an explicit end-of-life doctrine — from "should be disconnected if still in use" (2022) to "Users should discontinue utilization of the product" (2024–2025). When the vendor's fix column reads "Not Available," removal is the remediation.
Enterprise edge devices got a whole directive about this problem in 2026: BOD 26-02 orders agencies to inventory and decommission end-of-support firewalls, VPN gateways, and routers on a twelve-month clock — the population our EOS Edge Device List tracks. But the consumer and small-office tier below that — the DIR-859s and DSL gateways of the world — has no directive, no inventory requirement, and no decommission deadline. The KEV disconnect entries are the only standing federal signal that this hardware is actively dangerous, and they arrive one exploited CVE at a time, years after the vendor walked away.
What to do with this list
If you run any device on this page, the vendors and CISA agree on the remediation: replace it. There is no configuration that makes an unpatchable, actively-exploited device safe to keep on the internet. Beyond the specific models: treat vendor end-of-support dates as removal deadlines for anything that faces the network — the same discipline BOD 26-02 now enforces on federal edge fleets, applied one tier down. Our end-of-support hub explains the vocabulary, the EOS Edge Device List tracks the enterprise edge platforms with the same verified-at-the-vendor rigor as this article, and the Exploited & Unpatchable feed documents the cases where KEV-listed exploitation and end-of-life status collide with no fix on the affected line.
A note on what's not in this article
We verified two adjacent cases and left them out, because the evidence pointed the other way. DrayTek routers appear in the KEV catalog too — but DrayTek shipped firmware fixes for its listed CVEs, including on aging models, so it does not belong on an abandoned-hardware list. And WatchGuard's Firebox — whose T35-class models reached end of life on December 31, 2025 with two KEV entries close behind — published fixed builds specifically for those models, which disqualifies it from the no-patch pattern this article documents. That is the test every row above passed: the vendor's own advisory confirms no fix exists and none is coming.
Frequently Asked Questions
Which end-of-life routers are in CISA's KEV catalog?
Seven entries cover exploited flaws in vendor-abandoned devices: five against D-Link routers — CVE-2021-45382 (DIR-810L/820L/826L/830L/836L), CVE-2022-26258 and CVE-2023-25280 (DIR-820L), CVE-2019-17621 and CVE-2024-0769 (DIR-859) — and two against Zyxel legacy DSL gateways (CVE-2024-40890/40891). The D-Link models reached end of support between November 2017 and December 2020 per D-Link's own advisories; Zyxel says its affected models have been EOL "for years."
What does CISA tell agencies to do about these devices?
Disconnect them. Where most KEV entries require a patch by a due date, these read "The impacted product is end-of-life and should be disconnected if still in use" or "Users should discontinue utilization of the product." Under BOD 22-01 every KEV entry carries a mandatory remediation — and for a device that will never see another patch, the only remediation is removal.
How long after end of life do these devices keep getting exploited?
Up to seven years and counting in this set. DIR-820L: end of support November 1, 2017, KEV entry September 30, 2024. DIR-859: end of support December 10, 2020, KEV entry June 25, 2025 — for a vulnerability disclosed years after the last patch shipped. Exploitation does not wind down after end of support; the target just stops moving.
Will D-Link or Zyxel patch these vulnerabilities?
No. D-Link states EOL products "no longer receive device software updates and security patches," and the Fixed Firmware column in its own advisory table reads "Not Available" for every affected model; its recommendation is that the devices "be retired and replaced." Zyxel recommends replacing its affected DSL gateways with newer-generation products. Replacement is the fix.
Related
- The EOS Edge Device List — the enterprise tier of this same problem, 21 platforms verified at the vendor
- End of support & the BOD 26-02 clock · EOS vs EOL — what the terms actually mean
- Exploited & Unpatchable — KEV-listed exploitation meeting end-of-life, case by case
- BOD 26-04 & 26-02 explained — the federal directives on end-of-life software and edge devices