{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dir-x1860z--1.0.2.220120.165402/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:dlink:dir-x1860:*:*:*:*:*:*:*:*","cpe:2.3:h:dlink:dir-x1860z:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94036"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DIR-X1860 (\u003c= 1.0.2.220120.165402)","DIR-X1860Z (\u003c= 1.0.2.220120.165402)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-94036 affects D-Link DIR-X1860 and DIR-X1860Z router models running firmware versions up to 1.0.2.220120.165402. The flaw exists within the 'routerd' service, specifically in the handling of the '/ubus' component. An attacker positioned on the local network can manipulate the 'passwd_set' argument to bypass existing access controls. This vulnerability poses a significant risk to home and small office environments, as a publicly available exploit has been released, allowing potential unauthorized access or configuration changes to the affected networking hardware. Defenders should prioritize updating firmware where available or isolating vulnerable devices from untrusted local network segments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-94036 allows an attacker on the local network to gain unauthorized access or manipulate security controls on affected D-Link routers. This could lead to a complete compromise of the network gateway, enabling traffic interception, unauthorized configuration modifications, or the redirection of user traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all D-Link DIR-X1860 and DIR-X1860Z devices in the environment using asset management logs.\u003c/li\u003e\n\u003cli\u003ePatch affected devices to the latest firmware version released by D-Link beyond 1.0.2.220120.165402.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, restrict management interface access by placing vulnerable routers behind a segmented VLAN or firewall to ensure they are not accessible to unauthorized local network entities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T16:22:03Z","date_published":"2026-09-20T16:22:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-router-access-control/","summary":"D-Link DIR-X1860 and DIR-X1860Z routers are vulnerable to improper access control via the /ubus component in the routerd service, enabling local network attackers to exploit the passwd_set argument.","title":"Improper Access Control Vulnerability in D-Link DIR-X1860 Routers","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-router-access-control/"}],"language":"en","title":"CraftedSignal Threat Feed - DIR-X1860Z (\u003c= 1.0.2.220120.165402)","version":"https://jsonfeed.org/version/1.1"}