Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks. | |
| Title | D-Link DIR-X1860/DIR-X1860Z routerd ubus access control | |
| First Time appeared |
D-link
D-link dir-x1860 D-link dir-x1860z |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:h:d-link:dir-x1860:*:*:*:*:*:*:*:* cpe:2.3:h:d-link:dir-x1860z:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
D-link
D-link dir-x1860 D-link dir-x1860z |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T15:45:09.746Z
Reserved: 2026-09-19T17:54:14.840Z
Link: CVE-2026-94036
No data.
Status : Received
Published: 2026-09-20T16:16:55.490
Modified: 2026-09-20T16:16:55.490
Link: CVE-2026-94036
No data.
OpenCVE Enrichment
Updated: 2026-09-20T17:15:17Z
