CVE-2026-94036 HIGH

CVE-2026-94036: D-Link DIR-X1860/DIR-X1860Z routerd ubus access control

Vendor D-Link
Product DIR-X1860
Weakness CWE-284
Published September 20, 2026
Last update September 20, 2026

CVSS base score

8.7/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

Key dates

02Disclosure timeline

September 20, 2026 CVE published

Related vulnerabilities

04Related CVE