在 D-Link DIR-X1860 和 DIR-X1860Z(版本 1.0.2.220120.165402 及更早版本)中发现了一个安全漏洞。受影响的组件是 routerd 进程中文件 /ubus 的一个未知功能。通过对参数 passwd_set 的操控,可导致访问控制不当。攻击必须源自本地网络。该漏洞的利用工具已公开,可能被用于实施攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| D-Link | DIR-X1860 | 1.0.2.220120.165402 |
affected |
| D-Link | DIR-X1860Z | 1.0.2.220120.165402 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| D-Link | DIR-X1860 | 1.0.2.220120.165402 |
cpe:2.3:h:d-link:dir-x1860:*:*:*:*:*:*:*:*
|
|
| D-Link | DIR-X1860Z | 1.0.2.220120.165402 |
cpe:2.3:h:d-link:dir-x1860z:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94089 | 10.0 CRITICAL | D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow |
| CVE-2026-93958 | 9.1 CRITICAL | D-Link R95 DHMAPI ssi system os command injection |
| CVE-2026-94050 | 4.3 MEDIUM | D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosure |
No comments yet