• News/
  • https://www.bleepingcomputer.com/news/security/new-d-link-flaw-in-legacy-dsl-routers-actively-exploited-in-attacks/

New D-Link flaw in legacy DSL routers actively exploited in attacks

BleepingComputer
·
Bill Toulas
·
Published Jan 6, 2026
·
Updated

Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago. The vulnerability is now tracked as CVE-2026-0625 and affects the dnscfg.cgi endpoint due to improper input sanitization in a CGI library. An unauthenticated attacker could leverage this to execute remote commands via DNS configuration parameters. Vulnerability intelligence company VulnCheck reported the problem to D-Link on December 15, after The Shadowserver Foundation observed a command injection exploitation attempt on one of its honeypots. VulnCheck told BleepingComputer that the technique captured by Shadowserver does not appear to have been publicly documented. "An unauthenticated remote attacker can inject and execute arbitrary shell commands, resulting in remote code execution," VulnCheck says in the security advisory. In collaboration with VulnCheck, D-Link confirmed the following device models and firmware versions to be affected by CVE-2026-0625: The above have reached end-of-life (EoL) since 2020 and will not receive firmware updates to address CVE-2026-0625. Hence, the vendor strongly recommends retiring and replacing the affected devices with supported models. D-Link is still trying to determine if any other products are impacted by analyzing various firmware releases. "Both D-Link and VulnCheck face complexity in precisely identifying all impacted models due to variations in firmware implementa...

Read full article

Affected Software

1 affected component
D-Link DSL Gateway Router>0, <=2020
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a command injection vulnerability in legacy D-Link DSL routers that is being actively exploited by threat actors.

2

What security implications are discussed in the article?

The article highlights the risk of unauthorized access and control over affected routers due to the command injection vulnerability.

3

What products or software are affected by this vulnerability?

The vulnerability impacts D-Link DSL gateway routers that went out of support before 2020.

4

What is the identifier for this vulnerability?

The vulnerability is tracked as CVE-2026-0625.

5

Are there any recommendations for users of the affected routers?

Users are advised to cease using affected routers or take measures to secure their network until a fix is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203