D-Link: D-Link Router Flaws Let Unauthenticated Attackers Change Admin Password and Steal Wi-Fi Credentials

D-Link: D-Link Router Flaws Let Unauthenticated Attackers Change Admin Password and Steal Wi-Fi Credentials

D-Link Patches Critical Flaws in DIR-X1860Z Router Allowing Unauthorized Admin Access and Wi-Fi Credential Theft

D-Link has released a firmware update to address two critical vulnerabilities in its DIR-X1860Z router, which could allow unauthenticated attackers on a local network to hijack administrator access and steal Wi-Fi credentials.

The flaws, disclosed in D-Link advisory SAP10513 on August 26, 2026, were reported by security researcher Lim Kar Joon on August 18, 2026. They affect the non-US DIR-X1860Z (hardware revision A1) running firmware V1.0.2.220120.165402, stemming from weaknesses in the router’s OpenWrt-based ubus JSON-RPC management interface exposed via TCP port 23355 and the /ubus endpoint.

Vulnerability Breakdown

  1. Unauthenticated Password Change (Improper Access Control)

    • The routerd.passwd_set method could be exploited without authentication, allowing an attacker to set a new administrator password.
    • Once changed, the attacker could log in normally, gaining full control over router settings, network services, and device access rules.
  2. Wi-Fi Credential Theft (Information Disclosure)

    • The routerd.wificfg_get and routerd.get_rand_key methods exposed wireless configuration details, including Wi-Fi passwords.
    • Stolen credentials could enable persistent network access, unauthorized reconnections, or credential sharing.

D-Link classified the issues as improper access control, improper authorization, and information disclosure, though no CVE, CWE, or CVSS score has been assigned.

Patch and Mitigation

The vulnerabilities were resolved in firmware V1.0.7.260821.161908, released on August 25, 2026. Users must verify their device is the DIR-X1860Z (not the end-of-life DIR-X1860) before applying the update, as incorrect firmware installation could cause issues.

The DIR-X1860, a separate model, has reached end of life (EOL) and will no longer receive security updates. D-Link advises replacing it with a supported device.

Source: https://cybersecuritynews.com/d-link-router-flaws/

D-Link cybersecurity rating report: https://www.rankiteo.com/company/dlink-corp

"id": "DLI1788193422",
"linkid": "dlink-corp",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of DIR-X1860Z router '
                                              '(hardware revision A1)',
                        'industry': 'Technology/Networking',
                        'name': 'D-Link',
                        'type': 'Company'}],
 'attack_vector': 'Local Network',
 'customer_advisories': 'Users advised to update firmware or replace '
                        'end-of-life devices',
 'data_breach': {'sensitivity_of_data': 'High (Wi-Fi passwords, admin access)',
                 'type_of_data_compromised': 'Wi-Fi credentials, administrator '
                                             'passwords'},
 'date_detected': '2026-08-18',
 'date_publicly_disclosed': '2026-08-26',
 'date_resolved': '2026-08-25',
 'description': 'D-Link has released a firmware update to address two critical '
                'vulnerabilities in its DIR-X1860Z router, which could allow '
                'unauthenticated attackers on a local network to hijack '
                'administrator access and steal Wi-Fi credentials. The flaws '
                'stem from weaknesses in the router’s OpenWrt-based ubus '
                'JSON-RPC management interface exposed via TCP port 23355 and '
                'the /ubus endpoint.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'security flaws',
            'data_compromised': 'Wi-Fi credentials, administrator access',
            'operational_impact': 'Full control over router settings, network '
                                  'services, and device access rules',
            'systems_affected': 'DIR-X1860Z router (hardware revision A1)'},
 'investigation_status': 'Resolved',
 'post_incident_analysis': {'corrective_actions': 'Firmware patch to address '
                                                  'improper access control and '
                                                  'information disclosure',
                            'root_causes': 'Weaknesses in OpenWrt-based ubus '
                                           'JSON-RPC management interface (TCP '
                                           'port 23355 and /ubus endpoint)'},
 'recommendations': 'Users should verify their device model (DIR-X1860Z, not '
                    'DIR-X1860) and apply the firmware update '
                    'V1.0.7.260821.161908. End-of-life devices (DIR-X1860) '
                    'should be replaced with supported models.',
 'references': [{'date_accessed': '2026-08-26',
                 'source': 'D-Link Advisory SAP10513'}],
 'response': {'communication_strategy': 'Public advisory (SAP10513) issued on '
                                        'August 26, 2026',
              'containment_measures': 'Firmware update (V1.0.7.260821.161908) '
                                      'released to patch vulnerabilities',
              'remediation_measures': 'Applied firmware patch to resolve '
                                      'improper access control and information '
                                      'disclosure flaws'},
 'stakeholder_advisories': 'Public advisory issued to users of DIR-X1860Z '
                           'routers',
 'title': 'D-Link Patches Critical Flaws in DIR-X1860Z Router Allowing '
          'Unauthorized Admin Access and Wi-Fi Credential Theft',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': ['Improper Access Control (routerd.passwd_set '
                             'method)',
                             'Improper Authorization (routerd.wificfg_get and '
                             'routerd.get_rand_key methods)',
                             'Information Disclosure']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.