CVE-2026-0625 is a critical authentication bypass and improper access control vulnerability affecting multiple end-of-life D-Link DSL/DIR/DNS devices. It allows unauthenticated attackers to directly access and modify DNS settings via the dnscfg.cgi endpoint, enabling DNS hijacking attacks. With a CVSS score of 9.3 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, as it can redirect user traffic to malicious infrastructure. Active exploitation has been observed by the Shadowserver Foundation, and D-Link previously reported its leverage by the "GhostDNS" malware ecosystem. There is significant community discussion and media coverage, indicating high awareness, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| D-Link | DIR-600 | 0CNA affecteddefault unknown | |
| D-Link | DIR-608 | 0CNA affecteddefault unknown | |
| D-Link | DIR-610 | 0CNA affecteddefault unknown | |
| D-Link | DIR-611 | 0CNA affecteddefault unknown | |
| D-Link | DIR-615 | 0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.