ThreatCluster

D-Link DIR-X1860Z Vulnerabilities Allow Admin Password Reset by Unauthenticated Attackers

First seen 31 Aug 2026, 21:35 UTC GbhackersCybersecuritynews 58

Article Content

Browse articles
ThreatCluster

D-Link has released a firmware update addressing critical vulnerabilities in the DIR-X1860Z router. These flaws allow unauthenticated attackers on the local network to reset the administrator password and access wireless configuration details, including Wi-Fi credentials. The vulnerabilities affect the non-US hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. The security issues were disclosed in D-Link advisory SAP10513, published on August 26, 2026. Users are urged to apply the firmware update to mitigate these risks. The vulnerabilities pose a significant threat to home and small office networks, potentially exposing sensitive information. D-Link's advisory provides guidance on the update process for affected users.

Key Points: • D-Link's DIR-X1860Z router has critical vulnerabilities allowing password resets. • Unauthenticated attackers on local networks can access sensitive Wi-Fi configuration data. • Affected systems include non-US hardware revision A1/V1.0 with specific firmware.

Timeline

2026-08-26
D-Link advisory SAP10513 published
D-Link disclosed critical vulnerabilities affecting the DIR-X1860Z router, detailing the risks and necessary updates.
Cybersecuritynews
2026-08-31
Firmware update released
D-Link released a firmware update to address the vulnerabilities and mitigate risks for users.
Gbhackers