CVE-2026-0625Active Exploitation

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 8 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 8 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • General: 1 classified signal
  • Peaked 8d ago at 1 mentions (2026-02-09); latest day: 1
  • 9 total mentions across 9 days

Deep dive

Activity timeline9 mentions / 9d
00111Mentions · 2026-02-09: 1Mentions · 2026-03-01: 1Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-04: 1Mentions · 2026-04-07: 1Mentions · 2026-06-09: 1Mentions · 2026-06-15: 1Mentions · 2026-06-21: 1Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-21: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-02-09: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-07: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-15: 102-0903-0104-0104-0204-0404-0706-0906-1506-21
Signal classification2 categories
Active Exploitation
888.9%
General
111.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-091
Active Exploitation1
2026-03-011
General1
2026-04-011
Active Exploitation1
2026-04-021
Active Exploitation1
2026-04-041
Active Exploitation1
2026-04-071
Active Exploitation1
2026-06-091
Active Exploitation1
2026-06-151
Active Exploitation1
2026-06-211
Active Exploitation1
Full discourse9 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-0625 2 - CVE-2016-4655 3 - CVE-2025-27363 4 - CVE-2026-28515 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of five trending CVEs with no additional context or details.

    00010267
    1.7K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 UPDATE — AryStinger: No new attribution yet — but the pattern is unmistakable. AryStinger hits the SAME D-Link models (DIR-850L, DIR-818LW) previously targeted by AVrecon, which Lumen disrupted in 2023. And one of the vulnerabilities AryStinger uses (CVE-2025-11837) is from 2025 — meaning it's actively hunting newly discovered flaws. The broader context: D-Link DIR-823X routers are currently being exploited by Mirai variants via CVE-2025-29635, a flaw that went unexploited for a full year. D-Link DSL models are under attack from multiple gangs exploiting CVE-2026-0625. This isn't one botnet targeting one model — it's a coordinated ecosystem. End-of-life D-Link routers are the new botnet commons. Replace yours now. 👇 https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/

    Post summary

    The update confirms that several D‑Link router models (DIR‑850L, DIR‑818LW, DIR‑823X, and DSL) are being actively exploited by malware such as Mirai variants and multiple gangs using CVE‑2025‑11837, CVE‑2025‑29635, and CVE‑2026‑0625. No patches or PoC were cited, but the text underscores the immediate threat to end‑of‑life devices.

    0000070
    85 followersView on X
  • SHORT INFO@ShortInfoNews
    Active Exploitation

    Anyone still running an end-of-life D-Link DSL modem has an unpatchable bug being exploited now. CVE-2026-0625, CVSS 9.3, is command injection in dnscfg.cgi. DSL-526B, 2640B, 2740R, 2780B affected. Shadowserver tracked active exploitation since Nov 27. D-Link has no patch.

    Post summary

    The post highlights an unpatched command injection vulnerability (CVE‑2026‑0625) in several D‑Link DSL modem models that is actively exploited in the wild, with no vendor patch available.

    0000059
    152 followersView on X
  • ookin@neko@kal25252
    Active Exploitation

    🚨CVE-2026-0625(D-Link 旧型DSLルーター)を狙った攻撃を観測しました。 D-Link DSL-2740R、DSL-2640B、DSL-2780B、DSL-526Bなどの旧型DSLルーターにおけるリモートコード実行(RCE)の脆弱性です。 CVSSスコアは9.3(CRITICAL) 観測したパケットでは、64.118.132.61からDDosマルウェアをダウンロードするペイロードが仕込まれています。 MD5:2539fe7b4b465c24bcb8c1f064e4097f ご注意ください。

    Post summary

    Observed real‑world exploitation of CVE‑2026‑0625 on legacy D‑Link DSL routers via RCE, with malware downloaded from a known IP and a CVSS score of 9.3.

    00000182
    73 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Forest Blizzard exploited CVE-2026-0625 in legacy D-Link routers to hijack DNS settings and redirect traffic through attacker-controlled servers. The campaign enabled adversary-in-the-middle attacks against 200+ organizations, intercepting sensitive communications for intelligence collection. Runtime segmentation could help limit blast radius from compromised edge devices. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/forest-blizzard-2026-soho-router-dns-hijacking

    Post summary

    Forest Blizzard leveraged CVE‑2026‑0625 to hijack DNS on legacy D‑Link routers, creating an active MITM campaign that redirected traffic through attacker‑controlled servers and impacted over 200 organizations.

    0000051
    1.9K followersView on X
  • TheDarkForge@DarkForgeNews
    Active Exploitation

    [CYBERSEC] 𝗗-𝗟𝗶𝗻𝗸 𝗟𝗲𝗴𝗮𝗰𝘆 𝗥𝗼𝘂𝘁𝗲𝗿𝘀 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗦𝗶𝗻𝗰𝗲 𝗡𝗼𝘃𝗲𝗺𝗯𝗲𝗿, 𝗡𝗼 𝗣𝗮𝘁𝗰𝗵 𝗖𝗼𝗺𝗶𝗻𝗴 CVE-2026-0625 (CVSS 9.3), a command injection flaw in the dnscfg.cgi endpoint of D-Link DSL routers, has been actively exploited since November 2025, per Dark Reading. Affected models—DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B, manufactured 2016–2019—are end-of-life and will receive no security patch. — 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗘'𝗦 𝗪𝗘𝗜𝗚𝗛𝗧 Millions of unpatched routers face permanent zero-day exposure. Is this the new normal for IoT security? 𝘚𝘰𝘶𝘳𝘤𝘦𝘴: 𝘋𝘢𝘳𝘬 𝘙𝘦𝘢𝘥𝘪𝘯𝘨

    Post summary

    The post reports that CVE-2026-0625, a command‑injection flaw in D‑Link DSL routers, has been exploited in the wild since November 2025, and affected models—already end‑of‑life—will see no patch.

    0000043
    21 followersView on X
  • TheDarkForge@DarkForgeNews
    Active Exploitation

    [CYBERSEC] 𝗗-𝗟𝗶𝗻𝗸 𝗘𝗢𝗟 𝗗𝗲𝘃𝗶𝗰𝗲𝘀 𝗨𝗻𝗱𝗲𝗿 𝗔𝗰𝘁𝗶𝘃𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻 𝘃𝗶𝗮 𝗭𝗲𝗿𝗼-𝗗𝗮𝘆 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟬𝟲𝟮𝟱, 𝗡𝗼 𝗣𝗮𝘁𝗰𝗵 𝗖𝗼𝗺𝗶𝗻𝗴 Threat actors have been actively exploiting CVE-2026-0625 — a CVSS 9.3 authentication bypass zero-day (CWE-306) in the dnscfg.cgi endpoint of discontinued D-Link devices — since late November 2025, according to exploitation data confirmed by the Shadowserver Foundation. The flaw enables unauthenticated DNS hijacking. D-Link has issued no patch and will not; the affected models are end-of-life. D-Link has officially advised users to replace the hardware, leaving an unknown but substantial number of devices in homes and small businesses permanently exposed. With exploitation running uncontested for over four months and no vendor remediation path, the attack surface is frozen in place. The vulnerability sits in the dnscfg.cgi CGI endpoint, a component present across three discontinued D-Link product lines: DSL-series routers (including DSL-2740R, DSL-2640B, DSL-2780B, and others), DIR-series routers (DIR-600, DIR-608, DIR-615, DIR-905L, and others), and DNS-series NAS devices (DNS-320, DNS-325, DNS-345). All reached end-of-life by early 2020. The flaw is classified as CWE-306 — Missing Authentication for Critical Function, meaning unauthenticated attackers can send crafted requests to the dnscfg.cgi endpoint and manipulate DNS configuration without credentials or user interaction. The primary attack vector is DNS hijacking and traffic redirection. The endpoint enables both unauthenticated DNS hijacking (CWE-306) and OS command injection, resulting in RCE, according to VulnCheck's formal advisory and D-Link's SAP10488. The Shadowserver Foundation first observed in-the-wild attacks on November 27, 2025, meaning active exploitation predated VulnCheck's formal disclosure to D-Link by roughly three weeks and the public CVE designation by longer still. D-Link's end-of-life policy eliminates any obligation to patch, and the company has made that position explicit: replace the device. That instruction assumes users are monitoring vendor advisories and have both the means and the motivation to act. For a significant share of the small-business and residential install base these devices serve, neither assumption holds. The gap between 'device still routing traffic' and 'device owner aware of a critical zero-day' is where these compromises live. At a CVSS 4.0 base score of 9.3 (Critical), CVE-2026-0625 ranks among the more severe device vulnerabilities tracked this cycle. Unauthenticated access to DNS configuration on a network perimeter device gives an attacker a foothold that extends well beyond the device itself — traffic interception, credential harvesting from connected hosts, and redirection to attacker-controlled infrastructure all become viable follow-on actions. What remains unclear: the total number of vulnerable devices currently exposed to the internet and whether any threat actor group has been attributed to the active exploitation campaign. VulnCheck (the CVE's CNA) originated the formal disclosure in early January 2026; Shadowserver's telemetry is the primary empirical anchor for the exploitation timeline. D-Link's official advisory is SAP10488. — 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗘'𝗦 𝗪𝗘𝗜𝗚𝗛𝗧 D-Link's end-of-life policy is not a failure of security — it is security policy working exactly as designed, pricing continued support against commercial return, and finding the math unfavorable. The devices didn't become dangerous in November 2025; they became dangerous the moment the vendor's support window closed, and the installed base kept running anyway. What this event forces into view is the structural assumption beneath the consumer router market: that hardware lifecycles and user replacement cycles are synchronized, when the evidence consistently shows they are not. Who bears the cost of that gap — and why the answer has remained unchanged across a decade of identical incidents — is the question the industry has not found inconvenient enough to answer.

    Post summary

    CVE-2026-0625, a critical authentication bypass zero‑day in discontinued D‑Link routers, has been actively exploited in the wild since late 2025 with no available patch; users are advised to replace affected hardware.

    0000047
    20 followersView on X
  • TheDarkForge@DarkForgeNews
    Active Exploitation

    [CYBERSEC] **Unpatched D-Link Routers Under Active Exploit Since November 2025** A critical command injection vulnerability designated CVE-2026-0625 has been actively exploited in legacy D-Link DSL routers since at least November 2025, with no patch forthcoming from the manufacturer, according to reporting via Dark Reading and confirmed exploitation data from the Shadowserver Foundation. The flaw carries a CVSS score of 9.3, enabling unauthenticated remote code execution through the dnscfg.cgi endpoint — a network-facing interface that requires no credentials to reach on affected devices. Affected hardware includes four firmware variants: DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B. All four product lines reached end-of-life status in 2020, meaning D-Link ceased security support more than five years before the active exploitation campaigns were publicly identified. The company has confirmed it will not issue a patch, citing the devices' end-of-life classification. The Shadowserver Foundation, a nonprofit threat intelligence organization that monitors global internet attack surfaces, confirmed active exploitation campaigns targeting these devices at scale. The organization's honeypot and scanning infrastructure identified attack traffic consistent with automated exploitation of the dnscfg.cgi endpoint, suggesting threat actors have integrated the vulnerability into existing botnet recruitment toolchains rather than deploying it as a precision instrument. Command injection via CGI endpoints in consumer and small-office routers follows a well-established pattern. Mirai and its derivative botnets have historically leveraged unauthenticated RCE flaws in end-of-life networking equipment to assemble distributed denial-of-service infrastructure. Security researchers note that the DSL-series devices affected by CVE-2026-0625 are disproportionately concentrated in South and Southeast Asia, Eastern Europe, and parts of Latin America — regions where ISP-provisioned hardware replacement cycles lag significantly behind Western markets. The practical attack surface is difficult to quantify with precision. Shadowserver's internet-wide scans have identified tens of thousands of exposed devices, though the actual number of vulnerable units in active deployment is likely higher, as many sit behind carrier-grade NAT or are otherwise partially obscured from external enumeration. What is not in dispute is that devices responding to public internet queries on port 80 and 443 with D-Link DSL firmware fingerprints remain accessible and unmitigated. Security practitioners have offered blunt assessments of the incident's implications. 'There is no remediation path here except physical replacement,' said one network security researcher speaking to Dark Reading. 'You cannot patch hardware the vendor abandoned. The only question is how long these devices stay online, and historically, the answer is: much longer than anyone wants to admit.' A dissenting perspective worth noting comes from consumer advocacy circles, where critics argue that the framing of this as an 'end-of-life problem' obscures a structural failure in how networking hardware is brought to market. Devices sold with no contractual commitment to security updates, often bundled by ISPs and left in place for a decade or more, represent a systemic liability that individual users are poorly positioned to address. The end-of-life designation, critics contend, functions as a liability shield for manufacturers rather than a meaningful technical boundary. ISPs that provisioned these units in volume have not issued public statements regarding customer notification or subsidized replacement programs as of publication. CISA has not yet added CVE-2026-0625 to its Known Exploited Vulnerabilities catalog, though the active exploitation confirmation from Shadowserver meets the criteria the agency typically applies. Immediate mitigation guidance from security researchers: disable remote manage...

    Post summary

    CVE‑2026‑0625, a critical command‑injection flaw in end‑of‑life D‑Link routers, is being actively exploited in the wild since November 2025, with no vendor patch and only physical replacement as the advised mitigation.

    0000057
    20 followersView on X
  • Komodo Cyber Security@Komodosec
    Active Exploitation

    #VulnerabilityReport #CVE20260625 CVE-2026-0625: Critical Actively Exploited RCE Hits Unpatchable D-Link Routers https://securityonline.info/cve-2026-0625-critical-actively-exploited-rce-hits-unpatchable-d-link-routers/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet reports that CVE‑2026‑0625 is a critical remote code execution flaw in D‑Link routers that is currently being exploited in the wild and cannot be patched.

    0000045
    1.5K followersView on X

Explore more