Sceawere

Vulnerability Detail

CVE-2026-94036UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DIR-X1860 Improper Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
1h ago
Vendor
D-Link
Product
DIR-X1860
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-20T16:16:55.490Z",
  "pubdate": "2026-09-20T16:16:55.490Z",
  "executiveSummary": "A critical security vulnerability exists in the D-Link DIR-X1860 and DIR-X1860Z router models running firmware versions up to 1.0.2.220120.165402. The flaw resides within the routerd component's /ubus interface and manifests as an improper access control vulnerability triggered via the passwd_set argument.\nThis vulnerability allows an attacker located on the local network to bypass existing security controls, potentially leading to unauthorized modification of system credentials or administrative settings. The presence of publicly available exploit code significantly elevates the risk profile, as it lowers the barrier to entry for malicious actors. Exploitation does not necessarily require prior authentication, making it a severe threat to network integrity. Immediate mitigation is required to prevent unauthorized configuration changes or complete device compromise by local threat actors.",
  "technicalDetails": "The vulnerability is situated within the routerd component, specifically affecting the /ubus (ubusd) communication interface. Ubus is a common message bus system used in OpenWrt-based embedded firmware to facilitate inter-process communication (IPC) between various system services. The vulnerability is triggered by the improper handling of the passwd_set argument during a ubus call.\nThe root cause is an inadequate validation or authorization check performed by the routerd daemon when processing requests directed at the passwd_set functionality. Under normal operation, modifications to sensitive system parameters, such as passwords, should be restricted to authenticated administrative sessions. However, the implementation fails to strictly enforce these access control policies when receiving specific instructions through the /ubus socket.\nThe attack flow originates from the local network. An attacker can craft a malicious ubus message containing a specially formed passwd_set payload. Because the vulnerable function does not verify the identity or the privilege level of the caller, the system executes the command as requested by the unauthorized actor.\nStep-by-step exploitation involves the following: 1) The attacker establishes network access to the local area network. 2) The attacker targets the /ubus interface, which is typically accessible over local protocols. 3) The attacker issues a command via the ubus utility or a programmatic interface that invokes the passwd_set function within the routerd process. 4) The service processes the request without sufficient verification, allowing the attacker to influence or overwrite system credentials or modify administrative state variables. 5) By successfully manipulating the password or related configuration parameters, the attacker gains unauthorized control over the device, effectively escalating privileges to the level required to manage the administrative functions of the router.\nGiven that proof-of-concept exploits are publicly available, the risk is acute. Successful exploitation results in complete loss of administrative control, potential modification of device firmware or configuration settings, and potential interception of traffic if the attacker modifies DNS settings or VPN configurations via the authenticated control channel. The vulnerability persists across firmware versions up to 1.0.2.220120.165402, necessitating a firmware update or strict network-level isolation."
}
CVE-2026-94036: D-Link DIR-X1860 Improper Access Control (HIGH Severity, CVSS: 8.8) | Sceawere