Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Ongoing attack exploits critical RCE vulnerability in legacy D-Link DSL routers
Celebrities

Ongoing attack exploits critical RCE vulnerability in legacy D-Link DSL routers

By January 7, 2026No Comments1 Min Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 7, 2026Ravi LakshmananNetwork security/vulnerabilities

A newly discovered critical security flaw in legacy D-Link DSL gateway routers is being exploited in the wild.

The vulnerability, tracked as CVE-2026-0625 (CVSS score: 9.3), involves a case of command injection into the ‘dnscfg.cgi’ endpoint due to improper sanitization of user-specified DNS configuration parameters.

“An unauthenticated, remote attacker may be able to inject and execute arbitrary shell commands, potentially resulting in remote code execution,” VulnCheck said in its advisory.

“Affected endpoints are also associated with an unauthorized DNS change (“DNSChanger”) behavior documented by D-Link, which reported an active exploitation campaign targeting firmware variants of the DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B models from 2016 to 2019. ”

cyber security

The cybersecurity company also noted that an exploitation attempt targeting CVE-2026-0625 was recorded by the Shadow Server Foundation on November 27, 2025. Some of the affected devices have reached End of Life (EoL) status as of early 2020.

DSL-2640B <= 1.07 DSL-2740R < 1.17 DSL-2780B <= 1.01.14 DSL-526B <= 2.01

In its own alert, D-Link revealed that it initiated an internal investigation following VulnCheck’s December 16, 2025 report of active abuse of “dnscfg.cgi” and is working to determine past and current usage of the CGI library across all of its products.

He also noted that determining exactly which models are affected is complicated by different firmware implementations and product generations. An updated list of specific models will be published later this week once firmware level reviews are complete.

“Current analysis indicates that there is no reliable method of model number detection other than directly inspecting the firmware,” D-Link said. “For this reason, D-Link is validating firmware builds across legacy and supported platforms as part of our investigation.”

At this stage, the identity of the attackers exploiting this flaw and their scale are unknown. Because this vulnerability affects DSL gateway products that are being phased out, it is important that device owners retire those products and upgrade to actively supported devices that receive regular firmware and security updates.

cyber security

“CVE-2026-0625 exposes the same DNS configuration mechanisms utilized in past large-scale DNS hijacking campaigns,” Field Effect said. “This vulnerability allows unauthenticated remote code execution via the dnscfg.cgi endpoint, allowing an attacker to directly control DNS settings without credentials or user interaction.”

“Any changes to DNS entries can silently redirect, intercept, or block downstream traffic, resulting in a persistent compromise that affects all devices behind the router. The affected D-Link DSL models are end of life and cannot be patched, so organizations that continue to operate them face increased operational risk.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMcKinsey and General Catalyst executives say the days of ‘learn once and work forever’ are over
Next Article Enabling labs to protect what matters

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Trending Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.