A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulat…
High CVSS 8.8
Summary
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://pastebin.com/gzKNCCPV
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513
- https://vuldb.com/cve/CVE-2026-94036
- https://vuldb.com/submit/947565
- https://vuldb.com/vuln/407965
- https://vuldb.com/vuln/407965/cti
- https://www.dlink.com/
Timeline
- nvd_ingest NVD