Rewterz

CISA Warns of Exploited Microsoft SQL Server RCE Flaw

August 31, 2026
Rewterz

Microsoft Teams Abuse Leading to Enterprise Compromise – Active IOCs

September 3, 2026

D-Link Router Flaws Enable Credential Theft

Severity

High

Analysis Summary

D-Link has disclosed two security vulnerabilities in the DIR-X1860Z wireless router that could allow an unauthenticated attacker with access to the local network to compromise router administration and expose Wi-Fi credentials. The flaws were disclosed in D-Link advisory SAP10513, published on August 26, 2026, following a report from security researcher on August 18. The affected device is the non-US DIR-X1860Z, hardware revision A1, running firmware V1.0.2.220120.165402. Both vulnerabilities reside in the router’s OpenWrt-based ubus JSON-RPC management interface, which is exposed through TCP port 23355 and the /ubus endpoint.

The first vulnerability affects the routerd.passwd_set method, which could be accessed without proper authentication on the vulnerable firmware. An attacker already connected to the local network could exploit this weakness to change the router’s administrator password. Once the password was changed, the attacker could log in through the normal router management interface and obtain an authenticated ubus administrative session. This could provide extensive control over router management functions, allowing the attacker to modify network settings, services, connected-device access rules, and other administrative configurations.

The second vulnerability is an information-disclosure flaw involving the same ubus management interface. D-Link identified the affected functions as routerd wificfg_get and routerd.get_rand_key, which could be abused by an unauthorized local-network attacker to retrieve wireless configuration information, potentially including Wi-Fi credentials. Theft of these credentials could allow attackers to reconnect to the wireless network later, maintain unauthorized access, or share the credentials with other individuals. D-Link classified the issues as improper access control, improper authorization, and information disclosure; at the time of publication, no CVE, CWE classification, or official CVSS score had been assigned.

D-Link has addressed both vulnerabilities in DIR-X1860Z firmware V1.0.7.260821.161908, finalized on August 25, 2026, and recommends that affected users upgrade to this version or a newer release. Administrators should verify both the DIR-X1860Z model and hardware revision before updating, as D-Link specifically warns against installing DIR-X1860 firmware on DIR-X1860Z devices or vice versa. The similarly named DIR-X1860 is a separate non-US product that has reached end of life and end of service and will no longer receive security updates; users of that model should replace it with a supported router.

Impact

  • Gain Access

Remediation

  • Upgrade affected D-Link DIR-X1860Z A1 routers to firmware V1.0.7.260821.161908 or a newer supported release.
  • Confirm the device model and hardware revision before installing any firmware update.
  • Do not install DIR-X1860 firmware on DIR-X1860Z devices or DIR-X1860Z firmware on DIR-X1860 devices.
  • Replace the DIR-X1860, which has reached end of life and will no longer receive security updates.
  • Restrict access to the router’s ubus management interface, TCP port 23355, and /ubus endpoint from untrusted devices.
  • Use strong and unique administrator and Wi-Fi passwords to prevent unauthorized local-network access.
  • If compromise is suspected, change both the administrator and Wi-Fi passwords after updating the firmware.
  • Review router configurations, connected devices, and administrative activity for unauthorized changes or suspicious access.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.