{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3odlinkdap-1360_firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:dlink:dap-1360_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-95675"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DAP-1360 (\u003c= 6.14)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DAP-1360 wireless access points running firmware version 6.14 and earlier contain a critical vulnerability in the device's web management interface. This flaw allows an unauthenticated, remote attacker to execute arbitrary system commands with root privileges by sending specially crafted HTTP requests to the web management portal. Successful exploitation provides the attacker with full control over the device, facilitating persistent configuration changes and the ability to utilize the affected hardware as a pivot point for lateral movement into the local network. As this vulnerability impacts the management interface directly, the device can be compromised without requiring valid administrative credentials.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify D-Link DAP-1360 devices reachable via the web management interface.\u003c/li\u003e\n\u003cli\u003eAttacker probes the web interface to identify input parameters or endpoints vulnerable to command injection.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP request containing shell metacharacters targeted at the vulnerable management CGI or endpoint.\u003c/li\u003e\n\u003cli\u003eThe web server process, running as root, fails to sanitize the input and executes the injected payload.\u003c/li\u003e\n\u003cli\u003eThe device executes the attacker-supplied command, establishing an initial foothold.\u003c/li\u003e\n\u003cli\u003eAttacker modifies device configuration files to ensure persistence across reboots.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the compromised device as an internal jump host or proxy to scan and target other assets within the internal network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in total device compromise, allowing persistent unauthorized access to the network segment where the device is deployed. Threat actors can use the affected hardware for credential sniffing, traffic interception, or as a persistent gateway into secured network zones.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all D-Link DAP-1360 devices within the environment. If immediate patching is not possible, disable the remote web management interface or restrict access to the device management IP address to a dedicated, isolated management VLAN using firewall controls.\u003c/p\u003e\n","date_modified":"2026-09-22T14:36:25Z","date_published":"2026-09-22T14:36:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-rce/","summary":"D-Link DAP-1360 firmware version 6.14 and earlier is susceptible to unauthenticated remote code execution via the web management interface, allowing root-level command injection.","title":"Unauthenticated Remote Code Execution in D-Link DAP-1360","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:dlink:dap-1360_firmware:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}