Junglewise Threat Intelligence

CVE-2026-94036: D-Link DIR-X1860Z improper access control in ubus management interface

CVE-2026-94036 · Severity: high · CVSS 8.8 · Published 2026-09-20

Vendors: D-Link.

Executive brief

D-Link DIR-X1860Z routers contain a critical flaw in their network management interface that allows attackers on the local network to change the administrator password without authentication. An attacker exploiting this vulnerability can take complete control of the device, modify wireless and network settings, and access sensitive configuration data including Wi-Fi passwords.

Technical details

The ubus JSON-RPC management interface on the affected firmware fails to properly enforce access controls on the routerd.passwd_set method and related privileged methods, allowing unauthenticated requests from the local network to invoke administrative functions. The vulnerability is compounded by exposure of the AES encryption key through routerd.get_rand_key, enabling decryption and modification of password parameters. The flaw has been patched in firmware V1.0.7.260821.161908.

Affected products

  • D-Link DIR-X1860Z up to V1.0.2.220120.165402

Timeline

  • 2026-08-25: disclosed: Proof of concept exploit published on Pastebin
  • 2026-08-25: patched: Fixed firmware V1.0.7.260821.161908 released
  • 2026-08-26: advisory: D-Link security announcement SAP10513 published

References

Related threats