Executive brief
The D-Link DIR-X1860Z router's web management interface contains a flaw that allows unauthenticated attackers on the local network to access wireless configuration data, including WiFi credentials. An attacker with access to the router's network can extract sensitive wireless settings without needing to log in, compromising the security of wireless networks protected by that device.
Technical details
The vulnerability exists in the ubus JSON-RPC management interface (TCP port 23355), specifically in the routerd.wificfg_get and routerd.get_rand_key methods, which lack proper authentication checks. An unauthenticated attacker with local network access can call these methods to retrieve wireless configuration data including credentials. The issue is resolved in firmware version 1.0.7.260821.161908 and later.
Affected products
- D-Link DIR-X1860Z up to 1.0.2.220120.165402
Timeline
- 2026-08-18: disclosed
- 2026-08-25: patched: Firmware version 1.0.7.260821.161908 released
- 2026-09-20: advisory