Skip to main content
EPSS 1.0%top 40%

CVE-2026-0625: CWE-306 Missing Authentication for Critical Function in D-Link DSL-2640B

0
Critical
VulnerabilityCVE-2026-0625cvecve-2026-0625cwe-306
Published: 01/05/2026 (01/05/2026, 21:14:48 UTC)
Source: CVE Database V5
Vendor/Project: D-Link
Product: DSL-2640B

Description

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

D-Link

DSL-2640B

Affected versions
=0

D-Link

DSL-2740R

Affected versions
=0

D-Link

DSL-2780B

Affected versions
=0

D-Link

DSL-526B

Affected versions
=0

D-Link

DSL-2640T

Affected versions
=0

D-Link

DSL-500

Affected versions
=0

D-Link

DSL-500G

Affected versions
=0

D-Link

DSL-502G

Affected versions
=0

D-Link

DIR-905L

Affected versions
=0

D-Link

DIR-600

Affected versions
=0

D-Link

DIR-608

Affected versions
=0

D-Link

DIR-610

Affected versions
=0

D-Link

DIR-611

Affected versions
=0

D-Link

DIR-615

Affected versions
=0

D-Link

DNS-320

Affected versions
=0

D-Link

DNS-325

Affected versions
=0

D-Link

DNS-345

Affected versions
=0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 07:41:15 UTC

Technical Analysis

This vulnerability (CVE-2026-0625) involves missing authentication controls on the dnscfg.cgi endpoint of certain D-Link routers, including the DSL-2640B. An attacker can bypass authentication and directly access DNS configuration functions, allowing unauthorized modification of DNS settings. This can facilitate DNS hijacking attacks, redirecting users to attacker-controlled sites. The issue was publicly reported with a high CVSS score of 9.3 and has been exploited in the wild historically. The affected devices have been designated end-of-life and do not receive patches.

Potential Impact

Successful exploitation allows unauthenticated attackers to change DNS settings on vulnerable routers, enabling DNS hijacking. This can lead to user traffic interception, redirection to malicious sites, and potential further compromise of user systems. Since the devices are end-of-life, no official security updates are available to remediate this vulnerability.

Mitigation Recommendations

No patches or official fixes are available because all affected devices have reached end-of-life/end-of-service status. Users should replace vulnerable devices with supported models that receive security updates. Network administrators should consider isolating or discontinuing use of affected devices to prevent exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-01-05T20:59:29.705Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 695c2bac3839e441759217e3

Added to database: 01/05/2026, 21:22:52 UTC

Last enriched: 05/26/2026, 07:41:15 UTC

Last updated: 09/10/2026, 22:30:16 UTC

Views: 390

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses