A critical security vulnerability in legacy D-Link DSL gateway routers, identified as CVE-2026-0625 (CVSS score: 9.3), has been actively exploited. The flaw involves command injection through the “dnscfg.cgi” endpoint due to inadequate sanitization of user-supplied DNS configuration parameters. This allows unauthenticated remote attackers to inject malicious commands, posing a significant threat to affected devices. Users are urged to take immediate action to secure their routers against this exploit.
Want More Context? 🔎
Loading PerspectiveSplit analysis...






