QUOTE(OKLY @ Oct 16 2024, 08:21 PM)
Oh my..

Can’t help but wonder if they purposely don’t patch the CVEs due to some other motives..
that's a mystery,
either they don't know, or already patch but still there, or they don't care since because sold to TM cheap cheap
what I can told from my friend, they just say "not using known CVE", I guess they found a way to attack D-Link remotely even NATed via VLAN 209 to find another D-Link ONR.
whatever it is, ISP equipment is never been secure
TM not paid enough to maintain security since.
many people already using own Router that managed by Asus, TP-LINK, Mikrotik, Ubiquiti, etc... that have active security patches.
I know VLAN209 is for management, for good.
but once got a weak point, it come a checkpoint to crawl deeper within ISP private network
that is why old ONU Bridge since we been using are fine and never been use as Internet Routing.
all of sudden Unifi also offer ONR solution, trade off security for cheaper internet