D-Link: Seven Vulnerabilities Including RCE Disclosed in Single Batch
Key findings • Seven D-Link vulnerabilities disclosed between Sep 20-25, 2026, impacting multiple router and AP models. • Critical flaws include remote code execution and command injection, w…

Key findings
- Seven D-Link vulnerabilities disclosed between Sep 20-25, 2026, impacting multiple router and AP models.
- Critical flaws include remote code execution and command injection, with one public exploit available (CVE-2026-93958).
- Vulnerabilities range from buffer overflows and command injection to information disclosure and improper access controls.
- Affected devices include DIR-868L, DIR-X1860/Z, DAP-1360, DAP-2610, DIR-825, and R95 BE9500.
- Firmware updates are available for some models; users should consult D-Link advisories for specific patching details.
On September 25, 2026, a batch of seven vulnerabilities affecting various D-Link devices was disclosed, spanning a disclosure window from September 20th to September 25th. The vulnerabilities, ranging in severity from medium to critical, impact several D-Link router and access point models, including the DIR-868L, DIR-X1860/Z, DAP-1360, DAP-2610, DIR-825, and R95 BE9500. These flaws present significant risks, including remote code execution, command injection, buffer overflows, and improper access controls, with some allowing for remote exploitation.
Several critical vulnerabilities allow for remote code execution and command injection. CVE-2026-94089, a stack-based buffer overflow in the Authentication Handler component of the D-Link DIR-868L (up to 2.01b05), can be triggered remotely by manipulating the id/password arguments. Similarly, CVE-2026-95675, an unauthenticated remote code execution vulnerability in the D-Link DAP-1360 (firmware 6.14 and earlier), allows attackers to execute arbitrary commands as root without credentials by sending crafted requests to the web management interface. Another critical flaw, CVE-2026-93958, found in the D-Link R95 BE9500 (version 1.00.16), is an OS command injection vulnerability in the DHMAPI component, exploitable remotely by manipulating the NTPServer argument. The exploit for this vulnerability has been made public.
Further remote exploitation is possible through an out-of-bounds write vulnerability in the rp-l2tp component of the D-Link DIR-825 (3.00b32), identified as CVE-2026-96891. This flaw can be triggered by manipulating the peer_hostname argument in the tunnel_set_params function. Additionally, CVE-2025-51457, a high-severity authenticated command injection vulnerability in the D-Link DAP-2610 (up to 2.06B08r099), allows authenticated users to execute arbitrary system commands via the web interface at the /index.xgi endpoint.
The batch also includes vulnerabilities related to improper access controls and information disclosure, primarily affecting devices from within the local network. CVE-2026-94036, a high-severity flaw in the routerd component of D-Link DIR-X1860 and DIR-X1860Z (up to 1.0.2.220120.165402), results in improper access controls due to manipulation of the passwd_set argument. CVE-2026-94050, a medium-severity information disclosure vulnerability in the ubus JSON-RPC interface of D-Link DIR-X1860Z (up to 1.0.2.220120.165402), can be exploited from within the local network by manipulating routerd.wificfg_get/routerd.get_rand_key.
Users of affected D-Link devices are strongly advised to update their firmware to the latest available versions. For CVE-2025-51457, updating to version 2.06B08r100 or later is recommended. For CVE-2026-94050 and CVE-2026-94036, upgrading to version 1.0.2.220120.165402 or later is necessary. Specific patch information for CVE-2026-96891, CVE-2026-95675, CVE-2026-94089, and CVE-2026-93958 should be sought from D-Link's official advisories. Given the critical nature of some of these vulnerabilities, particularly those allowing remote code execution and the public exploit for CVE-2026-93958, prompt patching is essential to mitigate the risk of device compromise.
This coordinated disclosure highlights ongoing security challenges for D-Link products, underscoring the need for continuous vigilance and timely updates from users to protect their networks. The range of affected devices and vulnerability types indicates a broad need for security attention across D-Link's product lines.