A critical command injection vulnerability, tracked as CVE-2026-0625, has been discovered in multiple legacy D-Link DSL gateway routers. The flaw resides in the dnscfg.cgi endpoint, where improper input sanitization allows unauthenticated remote attackers to execute arbitrary shell commands via DNS configuration parameters. Security researchers from VulnCheck and The Shadowserver Foundation have confirmed active exploitation attempts, with evidence captured on honeypots and reports of ongoing campaigns targeting affected devices. The impacted models include DSL-526B (≤ 2.01), DSL-2640B (≤ 1.07), DSL-2740R (< 1.17), and DSL-2780B (≤ 1.01.14), all of which have reached end-of-life and will not receive security updates.
D-Link has acknowledged the vulnerability and is working to determine if additional products are affected, citing challenges in identifying all impacted models due to firmware variations. The company strongly advises users to retire and replace vulnerable devices, as no patches will be issued. The vulnerability is rated as critical (CVSS 9.3), and exploitation has been observed in the wild, though the specific threat actors and targets remain unclear. The risk is heightened by the unauthenticated nature of the exploit and the widespread use of these legacy routers in consumer environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
D-Link confirmed several impacted router models are end-of-life and will not receive security updates for the vulnerability. The vendor advised customers to replace unsupported devices with supported models instead of انتظار patches.
Public proof-of-concept exploit code for CVE-2026-0625 was made available on GitHub, lowering the barrier to exploitation. Reporting also recommended mitigations such as disabling remote administration, restricting management access, and replacing affected devices.
CVE-2026-0625 was disclosed as a critical command injection vulnerability in the dnscfg.cgi endpoint of multiple D-Link DSL gateways, allowing unauthenticated remote code execution. Public reporting noted a CVSS 4.0 score of 9.3 and active exploitation in the wild.
Following the report from VulnCheck, D-Link began reviewing firmware across its product lines to determine the full scope of impacted devices and versions. The company indicated it was still investigating because firmware variations made identification difficult.
After exploitation was observed, VulnCheck notified D-Link about the command injection issue affecting legacy DSL routers. SecurityAffairs states this report was made on December 16, 2025.
The Shadowserver Foundation detected exploitation attempts against the vulnerable dnscfg.cgi endpoint in late November 2025, providing evidence that the issue was being actively exploited in the wild. One report specifically dates this activity to November 27, 2025.
Several affected D-Link DSL gateway models, including DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B, were declared end-of-life in early 2020. Their unsupported status later meant no security patches would be issued for CVE-2026-0625.
Attack activity abusing similar unauthenticated DNS configuration weaknesses in D-Link routers was documented from at least 2016 through 2019 and beyond, including DNSChanger-style campaigns. Attackers used DNS hijacking to redirect traffic, distribute malware, and intercept communications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.