D-Link Routers Vulnerability Exploited by Hackers

D-Link Routers Vulnerability Exploited by Hackers

Critical D-Link Vulnerability Actively Exploited: CVE-2026-0625

A critical command injection vulnerability tracked as CVE-2026-0625 is being actively exploited in the wild, targeting numerous legacy D-Link DSL routers and gateways that reached end-of-life (EOL) years ago.

The flaw enables unauthenticated remote attackers to execute arbitrary shell commands via a DNS configuration endpoint, resulting in full remote code execution (RCE).

Discovery and Exploitation

The vulnerability was first reported by cybersecurity firm VulnCheck on December 16, 2025, after observing real-world exploitation attempts. Evidence of active attacks was independently confirmed by the Shadowserver Foundation, which detected malicious activity as early as November 27, 2025.

The root cause lies in improper input sanitization within the dnscfg.cgi endpoint of the router’s web interface. Attackers can inject shell commands into DNS configuration parameters without authentication, leading to complete system compromise. The flaw carries a CVSS v4 score of 9.3 (Critical).

Connection to GhostDNS/DNSChanger Campaigns

This vulnerability is part of a broader attack pattern linked to GhostDNS and DNSChanger campaigns, first documented in 2018–2019. These campaigns targeted home and carrier-grade routers using similar tactics—brute-forcing credentials or exploiting unprotected CGI scripts to hijack DNS settings for traffic interception and data theft. GhostDNS alone leveraged over 100 scripts and a vast infrastructure of more than 100 command-and-control servers.

Affected Devices

D-Link’s advisory lists at least 18 router and NAS models impacted by CVE-2026-0625, all of which are EOL/EOS and no longer receive security updates. Most were widely deployed between 2010 and 2016 in consumer and small office networks.

Confirmed affected models include:

  • DSL-526B (≤ v2.01)
  • DSL-2640B (≤ v1.07)
  • DSL-2740R (< v1.17)
  • DSL-2780B (≤ v1.01.14)

Additional devices linked to DNSChanger variants:

  • DSL series: DSL-2640T, DSL-2740R, DSL-500, DSL-500G, DSL-502G
  • DIR series routers: DIR-600, DIR-608, DIR-610, DIR-611, DIR-615, DIR-905L
  • ShareCenter NAS: DNS-320, DNS-325, DNS-345

No Patches – Immediate Action Required

D-Link has confirmed that no patches or mitigations will be released for these legacy devices and the company strongly advises users to retire affected hardware immediately, warning that continued use poses a significant security risk. Device replacement is the only viable defense.

Related Posts