CVE-2026-94036
8.8D-Link · DIR-X1860 and DIR-X1860Z
A critical improper access control vulnerability in D-Link DIR-X1860 and DIR-X1860Z routers allows unauthenticated attackers on the local network to change administrative passwords and hijack devices.
Executive summary
An unauthenticated remote code execution and device takeover vulnerability exists in D-Link DIR-X1860 routers, enabling attackers to reset administrative credentials and manipulate network configurations.
Vulnerability
The vulnerability resides in the routerd component, specifically within the /ubus endpoint, which fails to enforce proper capability checks for the passwd_set method. An unauthenticated attacker on the local network can invoke this function to overwrite the administrator password or alter critical wireless and WAN settings.
Business impact
Successful exploitation results in full administrative control over the affected networking hardware. This allows attackers to redirect traffic, intercept sensitive data, and persist within the internal network by modifying wireless or WAN configurations. Given the CVSS score of 8.8, the potential for total device compromise and subsequent lateral movement poses a high risk to organizational network integrity.
Remediation
Immediate Action: Update the affected D-Link routers to the latest available firmware version provided by the manufacturer. If an update is not immediately available, restrict access to the web management interface and the /ubus endpoint via network segmentation.
Proactive Monitoring: Review router configuration logs for unauthorized changes to administrative passwords or wireless settings. Monitor for unexpected traffic patterns originating from the management interface.
Compensating Controls: Implement strict network access control (NAC) to prevent unauthorized devices from reaching the management network. Place the router management interface in a dedicated, isolated VLAN accessible only by authorized administrative workstations.
Exploitation status
Public Exploit Available: Yes, a functional proof of concept and technical write-up are available via Pastebin.
Analyst recommendation
The severity of this vulnerability is elevated due to the ease of exploitation and the total loss of device integrity upon compromise. Organizations utilizing these D-Link models should prioritize firmware updates immediately. If patching is not possible, ensure that the administrative interface is not exposed to untrusted segments of the local network to prevent unauthenticated takeover.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by djzzlim (VulDB User), with djzzlim (VulDB User) (analyst), per the CVE Program record.
- VDB-407965 | D-Link DIR-X1860/DIR-X1860Z routerd ubus access control Vulnerability database entry
- VDB-407965 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-94036 | CVE Analysis and Report Third-party advisory
- Submit #947565 | D-Link DIR-X1860Z 1.0.2.220120.165402 Improper Access Controls Third-party advisory
- Related
- Exploit / PoC
- dlink.com