CVE-2026-0625

CRITICAL EXPLOITED

D-Link DSL/DIR/DNS - Unauthenticated DNS Configuration Modification via dnscfg.cgi Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-0625 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).

Scores

CVSS v4 9.3
EPSS 0.0096
EPSS Percentile 56.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-01-05
CWE
CWE-306
Status published
Products (17)
D-Link/DIR-600
D-Link/DIR-608
D-Link/DIR-610
D-Link/DIR-611
D-Link/DIR-615
D-Link/DIR-905L
D-Link/DNS-320
D-Link/DNS-325
D-Link/DNS-345
D-Link/DSL-2640B
... and 7 more
Published Jan 05, 2026
Tracked Since Feb 18, 2026