Skip to content
CVE Alert: CVE-2026-94036 – D-Link – DIR

CVE Alert: CVE-2026-94036 – D-Link – DIR

Redpacketsecurity admin September 20, 2026

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

## AI Summary Analysis

**Risk verdict:** Treat this as an urgent high-priority issue for deployments where untrusted users or devices can reach the router’s LAN, particularly because public exploitation material is available.

**Why this matters:** An unauthenticated attacker could potentially alter router credentials or configuration and gain control of the network edge. Likely objectives include traffic interception, DNS manipulation, denial of service, persistence, and using the router as a foothold for attacks against internal systems. KEV membership, SSVC exploitation status, and EPSS are not provided, so broader exploitation prevalence remains uncertain.

**Most likely attack path:** The attacker needs network adjacency but no account, special privileges, or victim interaction; low attack complexity makes compromised Wi-Fi clients, guest-network escapes, or an already-compromised LAN host realistic starting points. The unchanged scope suggests the immediate impact is concentrated on the device, although control of a gateway can enable lateral movement, credential theft, and redirection of downstream traffic.

**Who is most exposed:** Small offices, workers, and branch sites using these devices as unmanaged internet gateways are most vulnerable, especially where guest and corporate networks are not separated or administration is reachable from ordinary client segments.

Review router logs for unexpected requests to `/ubus`, especially `passwd_set` activity.

Alert on unplanned administrator-password, DNS, NAT, or firewall changes.

Compare configuration backups and firmware integrity against approved baselines.

Investigate unusual outbound traffic or new internal scanning from the router.

Mitigation and prioritisation:

Apply the vendor firmware remediation as soon as validated; treat as priority 1 if KEV or EPSS ≥ 0.5 is confirmed.

Restrict management and router-control interfaces to trusted administration hosts.

Isolate guest Wi-Fi and untrusted clients; replace unsupported devices.

Rotate administrative credentials and review configurations after patching, with a controlled reboot window.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities