Post updated September 20th, 2017 at 08:40 pm
UPDATE – 20/9 829pm: TM has finally released an official statement regarding the router and its upcoming firmware update. Learn more here.
UPDATE – 19/09 524pm: TIME Internet has issued a statement regarding DIR-850L router which also include a number of recommended interim safety measures. Check it out right here.
UPDATE – 19/09 106am: D-Link Malaysia will be releasing an update for its DIR-850L router soon. Read on this report for the full details.
UPDATE – 18/9 848pm: Several readers have pointed out that TIME Internet uses the same router too. More details below.
ORIGINAL STORY – 18/9 617pm: As part of its UniFi package, TM provides free routers to customers throughout the country including the cylindrical-shaped D-Link DIR-850L. If you are one such customer or even if you have purchased it separately, do note that there might be several critical security issues within your router.
This revelation was brought to light after security researcher Pierre Kim originally discovered it back in June, and published them online almost two weeks ago. There are plenty of issues according to the researcher, including unsecure firmware, backdoor access, weak files permission, credentials in cleartext, and many more.
In addition to that, the Cyber Security Agency of Singapore and Infocomm Media Development Authority have recently released a joint security advisory on the same router. The statement also stated that three more D-Link DIR-800 series routers including DIR-885L, DIR-890L, and DIR-895L are vulnerable as well.
D-Link has responded to the issue by releasing a statement that the company is already working to solve the flaws within its DIR-850L routers and will be releasing a firmware update for them on 19 September. The company has also recommended several rudimentary steps to help users protect themselves. including restoring the router’s default factory setting, and disable the WAN remote admin feature.
Meanwhile, we have reached out to TM regarding this issue and are now waiting for further details from the company. We’ll keep you posted once we hear any updates from them.
UPDATE – 848pm:
Several readers on our Facebook page have posted that TIME Internet has provided them with the same D-Link DIR-850L router too. In fact, it is clearly stated on the ISP’s official website that the router is given to customers as part of their 100Mbps and 300Mbps package.
We have since reached out to Time Internet regarding this issue and will keep you updated once they get back to us.
(Image: Brandon Leow)