HIGH 7.4 NVD
CVE-2026-94036
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
References
- https://pastebin.com/gzKNCCPV
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513
- https://vuldb.com/cve/CVE-2026-94036
- https://vuldb.com/submit/947565
- https://vuldb.com/vuln/407965
This high severity vulnerability with a CVSS score of 7.4 was published on 2026-09-20 via NVD.
vulnfeed aggregates 14834 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.