Sceawere

Vulnerability Detail

CVE-2026-95675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DAP-1360 Unauthenticated RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
D-LINK
Product
DAP-1360
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-22T14:17:22.230Z",
  "pubdate": "2026-09-22T14:17:22.230Z",
  "executiveSummary": "D-Link DAP-1360 firmware version 6.14 and earlier is susceptible to an unauthenticated Remote Code Execution (RCE) vulnerability within the web management interface. This critical security flaw allows remote, unauthenticated adversaries to execute arbitrary system commands with root-level privileges.\nThe vulnerability resides in the device's web management portal, where improper input validation enables attackers to inject and execute malicious code without requiring valid credentials. By successfully exploiting this flaw, an attacker gains complete control over the affected device.\nThe risk implications are severe, as the device acts as a persistent entry point into the internal network. Once compromised, the attacker can maintain long-term access, modify device configurations, exfiltrate sensitive data, or utilize the appliance as a pivot point for lateral movement within the local area network. Due to the lack of authentication requirements, the vulnerability can be exploited by any network entity capable of reaching the management interface, making it a high-priority threat for organizations and home users alike.",
  "technicalDetails": "The vulnerability in D-Link DAP-1360 firmware version 6.14 and earlier stems from a lack of secure input validation and command sanitization within the device's web management interface. The management service fails to verify the authenticity of incoming HTTP requests, effectively bypassing session management and authentication mechanisms for specific administrative endpoints.\nThe attack flow begins when an attacker sends a specially crafted HTTP request—typically leveraging POST or GET parameters—targeted at a vulnerable script or binary within the web server environment. Because the web management interface processes these inputs without proper filtering, the input is passed directly to an underlying system shell or sensitive system function.\nUpon processing the malformed request, the application treats the attacker-supplied input as executable system commands. Given the architectural design of these embedded firmware environments, the web server process typically runs with root permissions. Consequently, the injected payload is executed with the highest level of system privilege, providing the attacker full administrative control over the underlying Linux-based operating system.\nExploitation is facilitated by the network-exposed nature of the management interface. An attacker can reach the interface over the local network or, if misconfigured, via the WAN interface. No prior knowledge of administrative credentials is required, allowing for automated exploitation attempts by worms or remote actors.\nPost-exploitation activities include, but are not limited to, the installation of persistent backdoors, the modification of device configuration files (such as iptables rules or DNS settings), and the deployment of proxy services to tunnel traffic through the device. By pivoting into the local network, the attacker bypasses standard perimeter defenses, using the compromised DAP-1360 as an staging ground for further internal network enumeration and exploitation. The persistence mechanism is particularly dangerous, as the attacker can modify the device configuration to survive reboots, ensuring a continued foothold in the target network environment."
}
CVE-2026-95675: D-Link DAP-1360 Unauthenticated RCE (CRITICAL Severity, CVSS: 9.8) | Sceawere