CVE Feed

    Dashboard / CVE / CVE-2026-0625

    CVE-2026-0625

    Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).

    Published:Jan 5, 2026
    Last Modified:May 25, 2026
    EPS:Jan 5, 2026
    EPSS Score:0.00825
    CVSS Score:9.3

    Affected Products

    Vendor
    D-link
    Product
    Dsl-2640b
    Vendor
    D-link
    Product
    Dsl-2740r
    Vendor
    D-link
    Product
    Dsl-2780b
    Vendor
    D-link
    Product
    Dsl-526b
    Vendor
    Dlink
    Product
    Dsl-2640b Firmware
    Vendor
    Dlink
    Product
    Dsl-2640t
    Vendor
    Dlink
    Product
    Dsl-2640t Firmware
    Vendor
    Dlink
    Product
    Dsl-2740r
    Vendor
    Dlink
    Product
    Dsl-2740r Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High