GBHackers

D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft


D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials.

The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402.

D-Link addressed these issues in firmware version V1.0.7.260821.161908, which was finalized on August 25, 2026. The company published its advisory, SAP10513, on August 26 and urged affected users to update immediately.

According to D-Link’s advisory, the vulnerabilities arose from insufficient authentication and authorization checks in the router’s OpenWrt-based ubus JSON-RPC management interface.

The affected management service is exposed through TCP port 23355 at the /ubus endpoint. It relies on privileged routerd methods for device administration and configuration tasks.

Researcher Lim Kar Joon reported that the `routerd.passwd_set` method could be invoked without proper authentication. An attacker with access to the target’s local network could submit a request to change the router’s administrator password without knowing the current password.

Once the password is changed, the attacker could log in through the router’s standard authentication process and obtain an authenticated administrative `ubus_rpc_session`.

This access could enable them to fully take over the device’s management functions, depending on the privileges available to the administrative account.

The issue is classified as improper access control and improper authorization. While D-Link has not assigned a CVE identifier, a CWE mapping, or an authoritative CVSS score, the impact is significant because router administration controls network configuration, connected device visibility, DNS settings, port forwarding, firewall rules, and firmware update options.

D-Link also addressed a related information-disclosure vulnerability concerning wireless settings. The advisory states that interactions between the `routerd.wificfg_get` and `routerd.get_rand_key` methods could allow the recovery of wireless configuration information under the affected firmware.

The disclosed data may include wireless credentials, which could enable a local attacker to gain or maintain access to the victim’s Wi-Fi network.

Stolen Wi-Fi credentials could also be misused for unauthorized network access, attempts at lateral movement against connected systems, or persistent access after an administrator changes the router’s web management password.

Both vulnerabilities require local network access and are not categorized as direct internet-facing remote code execution vulnerabilities.

However, the requirement for local access should not be underestimated. Attackers can obtain this access through a compromised endpoint, a malicious insider, an unsecured guest network, previously leaked Wi-Fi credentials, or physical proximity to a poorly secured wireless network.

Administrators should confirm whether their device is specifically a DIR-X1860Z, verify its hardware revision, and install firmware version V1.0.7.260821.161908 or a later supported release. After installation, they should verify the running firmware version through the device’s administration interface.

D-Link emphasized that the patched DIR-X1860Z should not be confused with the similarly named DIR-X1860. The DIR-X1860 is an end-of-life product that will not receive any corresponding fixes, and users are encouraged to retire and replace it with a supported device.

The vendor also cautioned users against cross-installing firmware between the two models. The SAP10513 security announcement applies only to the DIR-X1860Z in non-US and global markets where the model was distributed.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link