{"id":"CVE-2026-94036","published":"2026-09-20T16:16:55.490","lastModified":"2026-09-21T17:19:18.847","description":"A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-266","CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://pastebin.com/gzKNCCPV","tags":[]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-94036","tags":[]},{"url":"https://vuldb.com/submit/947565","tags":[]},{"url":"https://vuldb.com/vuln/407965","tags":[]},{"url":"https://vuldb.com/vuln/407965/cti","tags":[]},{"url":"https://www.dlink.com/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A security flaw in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402 allows local network attackers to exploit improper access controls through manipulation of the passwd_set argument.","exploitability":"Exploitation requires local network access and manipulation of the passwd_set argument, making it moderately difficult to exploit.","blast_radius":"If exploited, the attack could lead to unauthorized access and control over the router, potentially leading to further network compromise.","remediation":"Upgrade to D-Link DIR-X1860 and DIR-X1860Z version 1.0.2.220120.165402 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["local-privilege-escalation","access-control","router"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:19:11.992Z"}}