D Link · Dir-X1860 · CVE-2026-94036
**Name of the Vulnerable Software and Affected Versions**
D-Link DIR-X1860 versions prior to 1.0.2.220120.165402
D-Link DIR-X1860Z versions prior to 1.0.2.220120.165402
**Description**
Improper access controls in the `routerd` component allow an attacker on the local network to bypass security measures. The issue occurs when the `passwd set` argument is manipulated within the `/ubus` endpoint.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.