<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>DIR-X1860 (&lt;= 1.0.2.220120.165402) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dir-x1860--1.0.2.220120.165402/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 16:22:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dir-x1860--1.0.2.220120.165402/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Access Control Vulnerability in D-Link DIR-X1860 Routers</title><link>https://feed.craftedsignal.io/briefs/2026-09-dlink-router-access-control/</link><pubDate>Sun, 20 Sep 2026 16:22:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dlink-router-access-control/</guid><description>D-Link DIR-X1860 and DIR-X1860Z routers are vulnerable to improper access control via the /ubus component in the routerd service, enabling local network attackers to exploit the passwd_set argument.</description><content:encoded><![CDATA[<p>A security vulnerability identified as CVE-2026-94036 affects D-Link DIR-X1860 and DIR-X1860Z router models running firmware versions up to 1.0.2.220120.165402. The flaw exists within the 'routerd' service, specifically in the handling of the '/ubus' component. An attacker positioned on the local network can manipulate the 'passwd_set' argument to bypass existing access controls. This vulnerability poses a significant risk to home and small office environments, as a publicly available exploit has been released, allowing potential unauthorized access or configuration changes to the affected networking hardware. Defenders should prioritize updating firmware where available or isolating vulnerable devices from untrusted local network segments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-94036 allows an attacker on the local network to gain unauthorized access or manipulate security controls on affected D-Link routers. This could lead to a complete compromise of the network gateway, enabling traffic interception, unauthorized configuration modifications, or the redirection of user traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all D-Link DIR-X1860 and DIR-X1860Z devices in the environment using asset management logs.</li>
<li>Patch affected devices to the latest firmware version released by D-Link beyond 1.0.2.220120.165402.</li>
<li>If a patch is unavailable, restrict management interface access by placing vulnerable routers behind a segmented VLAN or firewall to ensure they are not accessible to unauthorized local network entities.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>