CVE-2026-0625: Critical Actively Exploited RCE Hits Unpatchable D-Link Routers
ID: 5365538a-6370-56cf-8fda-17b881a33ec4
STIX ID: report--5365538a-6370-56cf-8fda-17b881a33ec4
Feed Name: securityonline.info
Security researchers disclosed CVE-2026-0625, a critical unauthenticated remote code execution vulnerability (CVSS v4.0 9.3) in the dnscfg.cgi DNS configuration endpoint of several legacy D-Link DSL router models (DSL-526B, DSL-2640B, DSL-2740R, DSL-2780B) running specified older firmware; Shadowserver observed active exploitation beginning Nov 27, 2025, and because these models were declared EOL with no patches planned, affected devices remain unpatchable and at high risk of compromise, botnet recruitment, or DNS manipulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
