Attackers Exploit Zero-Day in End-of-Life D-Link Routers
ID: 8b9dbbe6-9c62-5112-b8b1-16045d088595
STIX ID: report--8b9dbbe6-9c62-5112-b8b1-16045d088595
Feed Name: Dark Reading
A zero-day command-injection vulnerability (CVE-2026-0625, CVSS 9.3) in the dnscfg.cgi DNS configuration endpoint of multiple discontinued D-Link DSL gateway devices is being actively exploited in the wild; the flaw allows remote attackers to inject and execute arbitrary shell commands, potentially giving attackers perimeter footholds and the ability to pivot, persist, or exfiltrate data. D-Link is conducting a firmware-level review to identify affected models and recommends that organizations retire unsupported devices and replace them with currently supported hardware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
