Scworld Critical Vulnerability in D-Link Routers Exploited for Remote Code Execution
Article Content
Browse articles
A critical vulnerability, tracked as CVE-2026-0625, has been identified in legacy D-Link DSL gateway routers, allowing unauthenticated attackers to execute arbitrary commands remotely. The flaw, which has a CVSS score of 9.3, is due to inadequate sanitization of DNS configuration parameters, enabling command injection through the 'dnscfg.cgi' endpoint. This vulnerability is currently being exploited in the wild.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Mirai, VulnCheck and CVE-2026-0625 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Calix Router Flaw Exposes Home Networks to Attack A critical vulnerability in Calix GS5239XG routers, tracked as CVE-2026-75501, allows unauthenticated remote attackers to create port-forwarding rules, exposing internal devices to the internet. Discovered by researcher Brian Khan Quintana, the flaw stems from the router's UPnP control endpoint being accessible on the…
Massive Data Breach Exposes 220 Million Airline Records in Vietnam An exposed Advance Passenger Information System (APIS) database in Vietnam has leaked over 220 million records, including sensitive passenger and crew information such as passport numbers and flight details. Discovered by Kinryū Labs, the Elasticsearch cluster was accessible online due to a series of security…