Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago. The vulnerability is now tracked as CVE-2026-0625 and affects the dnscfg.cgi endpoint due to improper input sanitization in a CGI library. An unauthenticated attacker could leverage this to execute remote commands via DNS configuration parameters. Vulnerability intelligence company VulnCheck reported the problem to D-Link on December 15, after The Shadowserver Foundation observed a command injection exploitation attempt on one of its honeypots. VulnCheck told BleepingComputer that the technique captured by Shadowserver does not appear to have been publicly documented. "An unauthenticated remote attacker can inject and execute arbitrary shell commands, resulting in remote code execution," VulnCheck says in the security advisory. In collaboration with VulnCheck, D-Link confirmed the following device models and firmware versions to be affected by CVE-2026-0625: The above have reached end-of-life (EoL) since 2020 and will not receive firmware updates to address CVE-2026-0625. Hence, the vendor strongly recommends retiring and replacing the affected devices with supported models. D-Link is still trying to determine if any other products are impacted by analyzing various firmware releases. "Both D-Link and VulnCheck face complexity in precisely identifying all impacted models due to variations in firmware implementa...
New D-Link flaw in legacy DSL routers actively exploited in attacks
BleepingComputer
·Bill Toulas
·Published Jan 6, 2026
·Updated
Affected Software
1 affected component
D-Link DSL Gateway Router>0, <=2020
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a command injection vulnerability in legacy D-Link DSL routers that is being actively exploited by threat actors.
2
What security implications are discussed in the article?
The article highlights the risk of unauthorized access and control over affected routers due to the command injection vulnerability.
3
What products or software are affected by this vulnerability?
The vulnerability impacts D-Link DSL gateway routers that went out of support before 2020.
4
What is the identifier for this vulnerability?
The vulnerability is tracked as CVE-2026-0625.
5
Are there any recommendations for users of the affected routers?
Users are advised to cease using affected routers or take measures to secure their network until a fix is available.