CVE-2026-0625: CWE-306 Missing Authentication for Critical Function in D-Link DSL-2640B
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).
AI Analysis
Technical Summary
This vulnerability (CVE-2026-0625) involves missing authentication controls on the dnscfg.cgi endpoint of certain D-Link routers, including the DSL-2640B. An attacker can bypass authentication and directly access DNS configuration functions, allowing unauthorized modification of DNS settings. This can facilitate DNS hijacking attacks, redirecting users to attacker-controlled sites. The issue was publicly reported with a high CVSS score of 9.3 and has been exploited in the wild historically. The affected devices have been designated end-of-life and do not receive patches.
Potential Impact
Successful exploitation allows unauthenticated attackers to change DNS settings on vulnerable routers, enabling DNS hijacking. This can lead to user traffic interception, redirection to malicious sites, and potential further compromise of user systems. Since the devices are end-of-life, no official security updates are available to remediate this vulnerability.
Mitigation Recommendations
No patches or official fixes are available because all affected devices have reached end-of-life/end-of-service status. Users should replace vulnerable devices with supported models that receive security updates. Network administrators should consider isolating or discontinuing use of affected devices to prevent exploitation.
CVE-2026-0625: CWE-306 Missing Authentication for Critical Function in D-Link DSL-2640B
Description
Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without valid credentials, enabling DNS hijacking (“DNSChanger”) attacks that redirect user traffic to attacker-controlled infrastructure. In 2019, D-Link reported that this behavior was leveraged by the "GhostDNS" malware ecosystem targeting consumer and carrier routers. All impacted products were subsequently designated end-of-life/end-of-service, and no longer receive security updates. Exploitation evidence was observed by the Shadowserver Foundation on 2025-11-27 (UTC).
CVSS v4.0
Score 9.3critical
Affected software
D-Link
DSL-2640B
D-Link
DSL-2740R
D-Link
DSL-2780B
D-Link
DSL-526B
D-Link
DSL-2640T
D-Link
DSL-500
D-Link
DSL-500G
D-Link
DSL-502G
D-Link
DIR-905L
D-Link
DIR-600
D-Link
DIR-608
D-Link
DIR-610
D-Link
DIR-611
D-Link
DIR-615
D-Link
DNS-320
D-Link
DNS-325
D-Link
DNS-345
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-0625) involves missing authentication controls on the dnscfg.cgi endpoint of certain D-Link routers, including the DSL-2640B. An attacker can bypass authentication and directly access DNS configuration functions, allowing unauthorized modification of DNS settings. This can facilitate DNS hijacking attacks, redirecting users to attacker-controlled sites. The issue was publicly reported with a high CVSS score of 9.3 and has been exploited in the wild historically. The affected devices have been designated end-of-life and do not receive patches.
Potential Impact
Successful exploitation allows unauthenticated attackers to change DNS settings on vulnerable routers, enabling DNS hijacking. This can lead to user traffic interception, redirection to malicious sites, and potential further compromise of user systems. Since the devices are end-of-life, no official security updates are available to remediate this vulnerability.
Mitigation Recommendations
No patches or official fixes are available because all affected devices have reached end-of-life/end-of-service status. Users should replace vulnerable devices with supported models that receive security updates. Network administrators should consider isolating or discontinuing use of affected devices to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-05T20:59:29.705Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 695c2bac3839e441759217e3
Added to database: 01/05/2026, 21:22:52 UTC
Last enriched: 05/26/2026, 07:41:15 UTC
Last updated: 09/10/2026, 22:30:16 UTC
Views: 390
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.