Researchers have discovered a new vulnerability affecting older D-Link routers that don't receive security updates.
RondoDox botnet exploited React2Shell to compromise IoT devices and Next.js servers over a nine-month global campaign.
Old D-Link routers are being hijacked via a zero-day vulnerability, known as CVE-2026-0625, which allows attackers to remotely execute commands. No patch is currently available.