Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Unauthenticated OS Command Injection in D-Link dnscfg.cgi

IdentifiersCVE-2026-0625CWE-78· Improper Neutralization of Special…

CVE-2026-0625 is a critical OS command injection vulnerability in multiple legacy D-Link DSL gateway devices, including reported affected models DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B. The flaw is in the dnscfg.cgi endpoint that handles DNS configuration parameters. According to the provided content, the CGI library does not properly sanitize or validate user-supplied DNS settings before passing them to underlying system command processing. As a result, an unauthenticated remote attacker can supply crafted DNS configuration input containing shell metacharacters or injected commands and cause arbitrary shell command execution on the device. The same exposed functionality is also associated with unauthenticated DNS configuration changes, enabling DNSChanger-style hijacking. The issue has been reported as actively exploited in the wild, with exploitation evidence observed by the Shadowserver Foundation on 2025-11-27 UTC. All confirmed impacted products are described as end-of-life/end-of-service and no patches are expected for those models.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows unauthenticated remote code execution on the affected router or gateway, potentially resulting in full device compromise. An attacker can execute arbitrary shell commands, alter DNS settings to redirect or intercept downstream traffic, establish persistence, use the device as a proxy or botnet node, and leverage the router’s network-perimeter position for credential theft, traffic manipulation, lateral movement, or broader compromise of systems behind the device. Even where attackers only abuse the DNS configuration path, the impact includes DNS hijacking and redirection of user traffic to attacker-controlled infrastructure.

Mitigation

If you can’t patch tonight, do this now.

Because no patch is available for the confirmed end-of-life models, mitigation is compensating only. Remove or isolate affected devices wherever possible. Disable remote administration/WAN management if enabled. Restrict access to the web management interface to trusted management hosts or LAN segments only using ACLs, firewall rules, or upstream filtering. Place unavoidable legacy devices in segmented, non-critical network zones. Monitor for unauthorized DNS configuration changes and suspicious requests to dnscfg.cgi, and replace the hardware as soon as operationally feasible.

Remediation

Patch, then assume compromise.

The provided content indicates the affected confirmed devices are end-of-life/end-of-service and will not receive security updates for CVE-2026-0625. The primary remediation is to retire and replace affected D-Link devices with currently supported hardware receiving firmware and security maintenance. Where D-Link later identifies additional supported products with fixed firmware, those devices should be upgraded to the vendor-provided patched release after direct firmware/version verification.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
D-LinkDsl-2640bhardware
D-LinkDsl-2640b Firmwareoperating_system
D-LinkDsl-2640thardware
D-LinkDsl-2640t Firmwareoperating_system
D-LinkDsl-2740rhardware
D-LinkDsl-2740r Firmwareoperating_system
D-LinkDsl-2780bhardware
D-LinkDsl-526bhardware

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity33

Community discussion across Reddit, Mastodon, and other social sources.