PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94036 D-Link CVE debrief

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402, specifically in an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. This vulnerability allows attackers to bypass security controls, potentially leading to unauthorized access and data breaches. Defenders should assess exposure and prioritize verification and potential updates.

Vendor
D-Link
Product
DIR-X1860
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-20
Original CVE updated
2026-09-20
Advisory published
2026-09-20
Advisory updated
2026-09-20

Who should care

Defenders responsible for D-Link DIR-X1860 and DIR-X1860Z devices, especially those accessible from the local network, should assess exposure and prioritize verification and potential updates.

Why it matters

Defenders should prioritize verifying exposure of D-Link DIR-X1860 and DIR-X1860Z devices, especially those accessible from the local network, and assess the need for updates or compensating controls due to the improper access controls vulnerability.

  • Verify exposure of D-Link DIR-X1860 and DIR-X1860Z devices
  • Assess the need for updates or compensating controls
  • Monitor local network activity for potential attacks

Technical summary

The vulnerability is caused by improper access controls in an unknown function of the file /ubus of the component routerd. The attack must originate from the local network. This allows attackers to bypass security controls, potentially leading to unauthorized access and data breaches. The exploit has been released to the public and may be used for attacks. However, details about affected versions, exploitation, and remediation are sparse. Defenders should prioritize verifying exposure of D-Link DIR-X1860 and DIR-X1860Z devices, especially those accessible from the local network, and assess the need for updates or compensating controls.

Defensive priority

Defenders should prioritize verifying exposure of D-Link DIR-X1860 and DIR-X1860Z devices, especially those accessible from the local network, and assess the need for updates or compensating controls.

Recommended defensive actions

  • Verify exposure of D-Link DIR-X1860 and DIR-X1860Z devices, especially those accessible from the local network.
  • Assess the need for updates or compensating controls.
  • Monitor local network activity for potential attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The exploit has been released to the public and may be used for attacks. However, details about affected versions, exploitation, and remediation are sparse.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94036 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94036

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94036 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94036

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.