Skip to content
Threat Feed
medium advisory

Improper Access Control Vulnerability in D-Link DIR-X1860 Routers

D-Link DIR-X1860 and DIR-X1860Z routers are vulnerable to improper access control via the /ubus component in the routerd service, enabling local network attackers to exploit the passwd_set argument.

CVE search metadata

CVE search record: CVE-2026-94036. Severity: high. CVSS: 8.8. KEV: no. Product: DIR-X1860 (<= 1.0.2.220120.165402), DIR-X1860Z (<= 1.0.2.220120.165402). Brief: Improper Access Control Vulnerability in D-Link DIR-X1860 Routers. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-router-access-control/

A security vulnerability identified as CVE-2026-94036 affects D-Link DIR-X1860 and DIR-X1860Z router models running firmware versions up to 1.0.2.220120.165402. The flaw exists within the 'routerd' service, specifically in the handling of the '/ubus' component. An attacker positioned on the local network can manipulate the 'passwd_set' argument to bypass existing access controls. This vulnerability poses a significant risk to home and small office environments, as a publicly available exploit has been released, allowing potential unauthorized access or configuration changes to the affected networking hardware. Defenders should prioritize updating firmware where available or isolating vulnerable devices from untrusted local network segments.

Impact

Successful exploitation of CVE-2026-94036 allows an attacker on the local network to gain unauthorized access or manipulate security controls on affected D-Link routers. This could lead to a complete compromise of the network gateway, enabling traffic interception, unauthorized configuration modifications, or the redirection of user traffic.

Recommendation

  • Identify all D-Link DIR-X1860 and DIR-X1860Z devices in the environment using asset management logs.
  • Patch affected devices to the latest firmware version released by D-Link beyond 1.0.2.220120.165402.
  • If a patch is unavailable, restrict management interface access by placing vulnerable routers behind a segmented VLAN or firewall to ensure they are not accessible to unauthorized local network entities.

Immediate actions

Inventory all D-Link DIR-X1860 and DIR-X1860Z devices

IT Operations 24h

Mitigations

Update firmware to the latest available version beyond 1.0.2.220120.165402

immediate IT Operations

CVE-2026-94036