VYPR
patchPublished Aug 31, 2026· 1 source

D-Link Router Flaws Allow Unauthenticated Local Attackers to Change Admin Passwords and Steal Wi-Fi Credentials

Critical vulnerabilities in D-Link's DIR-X1860Z router enable unauthenticated local attackers to alter administrator passwords and extract Wi-Fi credentials.

D-Link has issued a firmware update to address critical security flaws affecting its DIR-X1860Z router, specifically impacting hardware revision A1 running firmware version V1.0.2.220120.165402. These vulnerabilities, disclosed in D-Link advisory SAP10513, could permit an unauthenticated attacker with local network access to change the router's administrator password and steal sensitive Wi-Fi credentials.

The security issues stem from flaws within the router's OpenWrt-based ubus JSON-RPC management interface, which is exposed via TCP port 23355 and the /ubus endpoint. This interface is managed by the device's routerd service, responsible for privileged router operations. The first vulnerability lies in the routerd.passwd_set method, which, on affected firmware, can be invoked without proper authentication.

An attacker who has already gained access to the victim's local network could exploit this flaw to set a new administrator password. Once the password is changed, the attacker can then use the standard router login process to establish an authenticated ubus session. This grants them administrative control over the device, enabling them to modify various router settings, network services, access rules for connected devices, and other critical configurations.

The second vulnerability is an information-disclosure flaw within the same ubus management interface. D-Link indicated that exposed routerd methods, specifically routerd.wificfg_get and routerd.get_rand_key, could be leveraged by unauthorized users to retrieve wireless configuration details. This includes the Wi-Fi network's credentials, which could be used to maintain persistent network access, reconnect later, or share with other malicious actors.

These vulnerabilities have been classified by D-Link as improper access control, improper authorization, and information disclosure. While no specific CVE identifiers or CVSS scores have been assigned at the time of reporting, the company has resolved both issues in DIR-X1860Z firmware version V1.0.7.260821.161908. The security update was finalized on August 25, 2026.

D-Link strongly urges affected users to install the fixed firmware release or any subsequent newer versions. Administrators are advised to confirm they possess the DIR-X1860Z model and the correct hardware revision before proceeding with the update. It is crucial to note that DIR-X1860Z firmware is not compatible with the similarly named DIR-X1860 model, which has reached its end of life and no longer receives security updates.

This incident highlights the ongoing risks associated with router security, particularly for devices accessible on local networks. Unauthenticated access to management interfaces can lead to significant compromise, including unauthorized control and data theft. Users are reminded to regularly check for and apply firmware updates to protect their home and business networks from such threats.

Synthesized by Vypr AI