D-Link has released a firmware update for critical access-control and information-disclosure flaws affecting its DIR-X1860Z router.
The vulnerabilities could allow an unauthenticated attacker connected to the local network to change the router administrator password and recover wireless configuration details, including Wi-Fi credentials.
The security issues were disclosed in D-Link advisory SAP10513, published on August 26, 2026. The company said it received the original report from security researcher Lim Kar Joon on August 18, 2026.
The affected product is the non-US D-Link DIR-X1860Z, hardware revision A1 running firmware V1.0.2.220120.165402. The vulnerabilities exist in the router’s OpenWrt-based ubus JSON-RPC management interface.
The interface is exposed via TCP port 23355 and the /ubus endpoint, where the device’s routerd service handles privileged router management operations. The first issue involves the routerd.passwd_set method.
D-Link Router Flaws
According to D-Link, the method could be called without proper authentication on vulnerable firmware. An attacker who already has access to the victim’s local network could potentially set a new administrator password for the router.
After changing the password, the attacker could use the normal router login process to obtain an authenticated administrative ubus session.
This would provide control over the device’s management functions and could enable further changes to router settings, network services, connected-device access rules, and other administrative configurations.
The second flaw is an information-disclosure issue in the same ubus management interface. D-Link said exposed routerd methods could allow unauthorized users to retrieve wireless configuration information.
The affected functions are routerd wificfg_get and routerd.get_rand_key. By interacting with those methods, an attacker on the local network could potentially recover Wi-Fi configuration data, including wireless credentials.
Stolen Wi-Fi passwords could allow an attacker to maintain access to the network, reconnect later, or share the credentials with other unauthorized users.
D-Link classified the findings as improper access control, improper authorization, and information disclosure. No CVE identifier, CWE classification, or official CVSS severity score has been assigned to the flaws at the time of publication.
The company resolved both issues in DIR-X1860Z firmware version V1.0.7.260821.161908. The firmware security update was finalized on August 25, 2026, and D-Link urges affected users to install the fixed release or a newer version when available.
Administrators should first confirm that their router is the DIR-X1860Z model and verify the applicable hardware revision before updating. D-Link warned users not to install DIR-X1860 firmware on a DIR-X1860Z device, or DIR-X1860Z firmware on a DIR-X1860.
The similarly named DIR-X1860 is a separate non-US product that has reached end of life and end of service. D-Link said the DIR-X1860 will no longer receive security updates and should be retired or replaced with a supported router. The current security update applies only to the active DIR-X1860Z product.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post D-Link Router Flaws Let Unauthenticated Attackers Change Admin Password and Steal Wi-Fi Credentials appeared first on Cyber Security News.
