CVE-2026-0625
D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint
Record summary
CVE-2026-0625 has a selected CVSS score of 9.3 (critical).
Description
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 5, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 20, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 18| Product | Source | Version range | Status |
|---|---|---|---|
D-Link DSLBrowse D-Link / D-Link DSL | VulnCheck | Version data not supplied | |
DIR-600Browse D-Link / DIR-600Default status: unknown | CVE List | Version range not supplied | affected |
DIR-608Browse D-Link / DIR-608Default status: unknown | CVE List | Version range not supplied | affected |
DIR-610Browse D-Link / DIR-610Default status: unknown | CVE List | Version range not supplied | affected |
DIR-611Browse D-Link / DIR-611Default status: unknown | CVE List | Version range not supplied | affected |
DIR-615Browse D-Link / DIR-615Default status: unknown | CVE List | Version range not supplied | affected |
DIR-905LBrowse D-Link / DIR-905LDefault status: unknown | CVE List | Version range not supplied | affected |
DNS-320Browse D-Link / DNS-320Default status: unknown | CVE List | Version range not supplied | affected |
DNS-325Browse D-Link / DNS-325Default status: unknown | CVE List | Version range not supplied | affected |
DNS-345Browse D-Link / DNS-345Default status: unknown | CVE List | Version range not supplied | affected |
DSL-2640BBrowse D-Link / DSL-2640BDefault status: unknown | CVE List | Version range not supplied | affected |
DSL-2640TBrowse D-Link / DSL-2640TDefault status: unknown | CVE List | Version range not supplied | affected |