D-Link Patches DIR-X1860Z Flaws Exposing Wi-Fi Credentials and Router Password Reset Risks
D-Link has released a security update for its DIR-X1860Z router after security researchers identified vulnerabilities that could allow an unauthenticated attacker on the local network to reset the administrator password and recover sensitive wireless configuration data, including Wi-Fi credentials.
The issues affect the non-US D-Link DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed the flaws in firmware version V1.0.7.260821.161908, finalized on August 25, 2026.
The company published security advisory SAP10513 on August 26 and urged affected customers to install the update immediately.
D-Link Patches DIR-X1860Z Flaws
According to D-Link, the vulnerabilities stem from insufficient authentication and authorization controls in the router’s OpenWrt-based ubus JSON-RPC management interface. The affected service is accessible through TCP port 23355 at the /ubus endpoint and exposes privileged routerd methods used for device management and configuration functions.
Researcher Lim Kar Joon reported that the routerd.passwd_set method could be invoked without adequate authentication. An attacker connected to the target’s local network could submit a request to modify the administrator password without supplying the existing password or a valid authenticated session.
After changing the password, the attacker could log in through the router’s normal web-based authentication process and obtain an authenticated administrative ubus_rpc_session. This session could potentially provide complete control over router administration features, depending on the permissions assigned to the administrator account.
Compromise of the administrative interface is significant because it can give an attacker control over DNS settings, firewall policies, port-forwarding rules, connected-device visibility, network configuration, and firmware-update settings. Attackers could abuse this access to redirect traffic, expose internal systems, monitor connected clients, or weaken security controls to maintain persistence.
D-Link did not assign a CVE identifier, CWE classification, or official CVSS score to the flaw. However, the issue involves improper access control and improper authorization in a privileged management interface.
D-Link also fixed a related information-disclosure vulnerability affecting wireless settings. The advisory stated that interactions between the routerd.wificfg_get and routerd.get_rand_key methods could enable recovery of wireless configuration information on vulnerable firmware versions.
The exposed information may include Wi-Fi credentials, creating an additional risk for users of affected devices. Stolen wireless passwords could allow attackers to obtain or maintain access to the network, even after the router’s web management password has been changed.
Access to Wi-Fi credentials can also support follow-on activity, including unauthorized network entry, reconnaissance of connected devices, lateral movement against internal systems, and persistent access to home or small-office networks.
In environments where the same wireless password is reused across multiple locations or devices, the impact could extend beyond the initially compromised router.
Both flaws require an attacker to already have local-network access. They are not categorized as internet-facing remote code execution vulnerabilities.
However, local access should not be treated as a minor barrier. Attackers may gain access through compromised endpoints, malicious insiders, poorly isolated guest networks, exposed wireless networks, physical proximity, or previously leaked Wi-Fi credentials.
Mitigation
Administrators should verify that their router is the DIR-X1860Z model, confirm the hardware revision, and update the firmware to version V1.0.7.260821.161908 or a later supported release. After installation, users should verify the active firmware version through the router’s administration interface.
D-Link cautioned that the patched DIR-X1860Z must not be confused with the similarly named DIR-X1860. The DIR-X1860 is an end-of-life product and will not receive corresponding fixes. Users operating that model should retire and replace it with a supported router.
The company also warned against cross-installing firmware between the DIR-X1860Z and DIR-X1860 models. SAP10513 applies only to the non-US and global-market DIR-X1860Z router variants.
No Comment! Be the first one.