Executive brief
D-Link DIR-X1860Z routers contain a critical flaw in their network management interface that allows attackers on the local network to change the administrator password without authentication. An attacker exploiting this vulnerability can take complete control of the device, modify wireless and network settings, and access sensitive configuration data including Wi-Fi passwords.
Technical details
The ubus JSON-RPC management interface on the affected firmware fails to properly enforce access controls on the routerd.passwd_set method and related privileged methods, allowing unauthenticated requests from the local network to invoke administrative functions. The vulnerability is compounded by exposure of the AES encryption key through routerd.get_rand_key, enabling decryption and modification of password parameters. The flaw has been patched in firmware V1.0.7.260821.161908.
Affected products
- D-Link DIR-X1860Z up to V1.0.2.220120.165402
Timeline
- 2026-08-25: disclosed: Proof of concept exploit published on Pastebin
- 2026-08-25: patched: Fixed firmware V1.0.7.260821.161908 released
- 2026-08-26: advisory: D-Link security announcement SAP10513 published