Hackers actively exploit critical RCE flaw in legacy D-Link DSL routers
ID: 1fd07a6b-1279-50ee-9f0c-d98cc2a5cb99
STIX ID: report--1fd07a6b-1279-50ee-9f0c-d98cc2a5cb99
Feed Name: Security Affairs
Threat Score
A critical unauthenticated RCE (CVE-2026-0625, CVSS 9.3) in the dnscfg.cgi endpoint of legacy D-Link DSL routers allows remote command injection; security researchers (VulnCheck, Shadowserver) observed active exploitation of affected DSL models, many of which reached end-of-life. D-Link is investigating firmware variants to identify impacted models and recommends replacing obsolete devices and applying updates where available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
