D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint
Summary
| CVE | CVE-2026-0625 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-01-05 22:15:54 UTC |
| Updated | 2026-04-15 00:35:42 UTC |
| Description | Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC). |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.008250000 probability, percentile 0.746880000 (date 2026-05-27)
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | D-Link | DSL-2640B | affected | Not specified |
| CNA | D-Link | DSL-2740R | affected | Not specified |
| CNA | D-Link | DSL-2780B | affected | Not specified |
| CNA | D-Link | DSL-526B | affected | Not specified |
| CNA | D-Link | DSL-2640T | affected | Not specified |
| CNA | D-Link | DSL-500 | affected | Not specified |
| CNA | D-Link | DSL-500G | affected | Not specified |
| CNA | D-Link | DSL-502G | affected | Not specified |
| CNA | D-Link | DIR-905L | affected | Not specified |
| CNA | D-Link | DIR-600 | affected | Not specified |
| CNA | D-Link | DIR-608 | affected | Not specified |
| CNA | D-Link | DIR-610 | affected | Not specified |
| CNA | D-Link | DIR-611 | affected | Not specified |
| CNA | D-Link | DIR-615 | affected | Not specified |
| CNA | D-Link | DNS-320 | affected | Not specified |
| CNA | D-Link | DNS-325 | affected | Not specified |
| CNA | D-Link | DNS-345 | affected | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| supportannouncement.us.dlink.com/security/publication.aspx | [email protected] | supportannouncement.us.dlink.com | |
| www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-... | [email protected] | www.vulncheck.com | |
| supportannouncement.us.dlink.com/announcement/publication.aspx | [email protected] | supportannouncement.us.dlink.com | |
| supportannouncement.us.dlink.com/security/publication.aspx | [email protected] | supportannouncement.us.dlink.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: The Shadowserver Foundation (en)
CNA: VulnCheck (en)
Additional Advisory Data
Solutions
CNA: D-Link Systems, Inc. recommends retiring these products and replacing them with products that receive firmware updates.
There are currently no legacy QID mappings associated with this CVE.