OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-95675

CRITICAL · CVSS 9.8 EPSS 2.06% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

D-Link DAP-1360 devices running firmware version 6.14 and earlier are vulnerable to an unauthenticated remote code execution flaw, enabling attackers to execute arbitrary commands as root via crafted requests to the web management interface. This critical vulnerability allows for full device compromise, potentially leading to persistent configuration changes and unauthorized access to the local network. Organizations using these devices should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95675
Severity
CRITICAL
CVSS
9.8
EPSS
2.06%

Original NVD Description

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.