Skip to content

Hackers actively exploit critical RCE flaw in legacy D

Securityaffairs.Co Pierluigi Paganini January 7, 2026

Attackers are exploiting a critical flaw (CVE-2026-0625) in old D-Link DSL routers that allows remote command execution. Threat actors are actively exploiting a critical RCE flaw, tracked as CVE-2026-0625 (CVSS score of 9.3), in legacy D-Link DSL routers. The vulnerability is an improper neutralization of special elements used in an OS Command (‘OS Command Injection’), […]

Extracted Entities

CVEs (1)