D-Link DSL gateway zero-day CVE-2026-0625: CVSS 9.3 command injection in dnscfg.cgi, no patch coming for EOL routers, Shadowserver tracked active exploitation since Nov 27 2025
Anyone still running an end-of-life D-Link DSL modem has an unpatchable bug. CVE-2026-0625 is a CVSS 9.3 command injection in dnscfg.cgi. Unauthenticated attackers seize the device. DSL-526B, 2640B, 2740R and 2780B are affected. Shadowserver has tracked active exploitation since
Anyone still running an end-of-life D-Link DSL modem at home or in a small office has an unpatchable bug being exploited in the wild right now. CVE-2026-0625 is a critical command injection vulnerability in the dnscfg.cgi endpoint, which handles DNS server settings on a number of legacy DSL gateways. The router fails to validate or sanitize user input before passing it into DNS configuration commands, allowing an unauthenticated remote attacker to execute arbitrary shell commands on the device. The vulnerability carries a CVSS score of 9.3. Affected models include the D-Link DSL-526B, DSL-2640B, DSL-2740R and DSL-2780B. All four have been out of D-Link's active support window for at least five years, which means they no longer receive firmware updates, security patches, or any maintenance support. No fix is coming. The Shadowserver Foundation first observed evidence of in-the-wild exploitation on November 27, 2025, well before the broader security community was alerted. D-Link said it was officially informed about the flaw on December 16, 2025, by VulnCheck. The vendor's recommendation is straightforward: retire the affected products and replace them with currently supported models. Home users and small businesses still running these legacy DSL gateways as their internet edge device sit on an exposed remote code execution surface that no patch will close.