There is no patch coming for this one. The vendor stopped making them.

CVE-2026-0625 — CVSS 9.3 — arbitrary shell command execution on discontinued D-Link DSL gateway devices, actively exploited through a compromised CGI library. VulnCheck confirmed exploitation in production environments. End-of-life means end of support, not end of exposure.

WHAT MAKES THIS DIFFERENT FROM A NORMAL ZERO-DAY

Most zero-day advisories end with a patch timeline. This one does not have one, because D-Link stopped supporting these DSL gateways. The CGI library flaw lets an unauthenticated attacker execute arbitrary shell commands directly on the device.

A device that will never receive a fix is not a vulnerability to track. It is a permanent open door until the hardware is physically removed.

WHY END-OF-LIFE NETWORK GEAR IS THE BLIND SPOT MOST ASSET INVENTORIES MISS

Vulnerability management programs are built around patch cycles. EOL devices break that model entirely — there is no cycle, no advisory to act on, no vendor SLA. They sit on inventory lists as "networking equipment," indistinguishable from supported devices, until something like this happens.

Small offices, branch locations, and home-office VPN endpoints are exactly where EOL gateways survive longest. Nobody budgets to replace a router that still passes traffic.

WHAT TO DO NOW

INVENTORY EOL NETWORK HARDWARE SPECIFICALLY — most asset management treats "still functioning" as "still supported." Separate the two categories explicitly.

CHECK FOR CVE-2026-0625 INDICATORS — VulnCheck has published detection guidance for the compromised CGI library. Compare against any D-Link DSL gateway still in service.

REPLACE, DO NOT MITIGATE — there is no firmware fix in the pipeline. Compensating controls buy time. They do not close the door.

SEGMENT WHAT YOU CANNOT REPLACE TODAY — if immediate replacement is not possible, isolate the device from any network segment carrying sensitive traffic until it is retired.

AUDIT REMOTE AND BRANCH SITES FIRST — this is where EOL gear survives unnoticed longest, and where nobody is watching it closely.

A device stops being your vendor's problem the day they stop supporting it. It never stops being your problem.

Do you know how many end-of-life devices are still passing traffic on your network right now?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.