OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94036

HIGH · CVSS 8.8 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

D-Link DIR-X1860 and DIR-X1860Z routers up to version 1.0.2.220120.165402 are vulnerable due to improper access controls in the routerd component, specifically within the /ubus file when manipulating the passwd_set argument. This flaw allows an attacker on the local network to exploit the vulnerability, potentially compromising the router's security. Network administrators and users of the affected D-Link models should prioritize applying updates to mitigate the risk of local exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94036
Severity
HIGH
CVSS
8.8
EPSS
0.56%

Original NVD Description

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.