New D-Link flaw in legacy DSL routers actively exploited in attacks
ID: 1fa47984-ffea-54bc-8158-5c43fd956b84
STIX ID: report--1fa47984-ffea-54bc-8158-5c43fd956b84
Feed Name: Bleeping Computer
Threat Score
A command injection vulnerability (CVE-2026-0625) affecting the dnscfg.cgi endpoint in multiple legacy D-Link DSL gateway routers allows unauthenticated remote command execution; Shadowserver observed exploitation attempts, VulnCheck reported the issue, and D-Link confirmed specific end-of-life models are impacted and will not receive patches, advising users to retire or segment affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
