{"id":"CVE-2026-94036","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-94036","summary":"A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd.…","details":"A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.","published":"2026-09-20T16:16:55.490","modified":"2026-09-20T16:16:55.490","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://pastebin.com/gzKNCCPV"},{"type":"WEB","url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-94036"},{"type":"WEB","url":"https://vuldb.com/submit/947565"},{"type":"WEB","url":"https://vuldb.com/vuln/407965"},{"type":"WEB","url":"https://vuldb.com/vuln/407965/cti"},{"type":"WEB","url":"https://www.dlink.com/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-20T16:16:55.490"}}