Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers
Legacy D-Link DSL gateway routers have a recently identified major security issue that is being actively exploited in the field.
The vulnerability, identified as CVE-2026-0625 (CVSS score: 9.3), relates to a command injection situation in the "dnscfg.cgi" endpoint that results from inadequate sanitization of DNS configuration parameters submitted by the user. According to a VulnCheck advisory, an unauthenticated remote attacker can inject and run arbitrary shell commands, leading to remote code execution.
D-Link confirmed active exploitation operations targeting firmware variants of the DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B models from 2016 to 2019. The impacted endpoint is also linked to unauthenticated DNS alteration ('DNSChanger') behavior.
The cybersecurity firm also ...

