在 D-Link DIR-X1860Z(版本 1.0.2.220120.165402 及更早版本)中发现了一个安全漏洞。该漏洞影响 ubus JSON-RPC 接口组件中的 和 函数。通过恶意利用这些函数,攻击者可获取敏感信息,导致信息泄露。此类攻击需从本地网络内部发起。升级至版本 1.0.7.260821.161908 可解决此问题,建议将受影响组件升级至该版本。需要注意的是,该漏洞仅影响维护者已不再提供支持的产品。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| D-Link | DIR-X1860Z | 1.0.2.220120.165402 |
cpe:2.3:h:d-link:dir-x1860z:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94089 | 10.0 CRITICAL | D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow |
| CVE-2026-93958 | 9.1 CRITICAL | D-Link R95 DHMAPI ssi system os command injection |
| CVE-2026-94036 | 8.8 HIGH | D-Link DIR-X1860/DIR-X1860Z routerd ubus access control |
No comments yet