A new critical vulnerability , discovered in older D-Link DSL gateway routers, has begun to be actively exploited by cybercriminals. The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), concerns a command injection in the “dnscfg.cgi” endpoint. It results from improper sanitization of user-supplied DNS configuration parameters.

“ An unauthenticated remote attacker can insert and execute arbitrary shell commands, resulting in code execution remote ,” VulnCheck noted in an advisory report.
“The affected endpoint is also associated with unauthorized DNS modification behavior ('DNSChanger') that has been documented by D-Link. The company reported active exploit campaigns targeting firmware variants of the DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B models from 2016 to 2019.“.
See also: AdonisJS Bodyparser: Critical vulnerability allows writing files to the server
The cybersecurity firm also noted that exploit attempts targeting CVE-2026-0625 were recorded by the Shadowserver Foundation on November 27, 2025.
Vulnerable D-Link DSL gateway routers
Some of the affected devices have reached end-of-life (EoL) status since early 2020:
- DSL-2640B <= 1.07
- DSL-2740R < 1.17
- DSL-2780B <= 1.01.14
- DSL-526B <= 2.01

D-Link began an internal investigation following a VulnCheck report on December 16, 2025, regarding the active exploitation of “dnscfg.cgi” and is working to identify past and current use of the CGI across all of its products. The company also said that it is difficult to pinpoint the exact models affected due to differences in firmware implementations and product generations.
An updated model list is expected to be published later this week, once a firmware-level review is completed.
See also: Eaton vulnerabilities allow malicious code to run on the system
“ Current analysis indicates that there is no reliable method of detecting model numbers beyond direct inspection of the firmware ,” D-Link said . “ For this reason, D-Link is validating firmware versions on legacy and supported platforms as part of the investigation .”
At this stage, the identity of the attackers exploiting the vulnerability and the scale of the efforts are unknown.
Since the vulnerability affects discontinued DSL gateway products, device owners should retire vulnerable routers and upgrade to devices that are actively supported and receive updates firmware and security

“CVE-2026-0625 exposes the same DNS configuration mechanism used in previous large-scale DNS hijacking campaigns,” Field Effect said. “The vulnerability allows unauthenticated remote code execution via the dnscfg.cgi endpoint, giving attackers direct control over DNS settings without credentials or user interaction.”
See also: Zero-day vulnerabilities: Why they're on the rise and who pays the price
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“Once modified, DNS entries can silently redirect, intercept, or block downstream traffic, resulting in a persistent breach that affects every device behind the router. Because the affected D-Link DSL models are end-of-life and cannot be repaired, organizations that continue to use them face increased operational risk.“.
