CVE-2026-94050 Overview
CVE-2026-94050 is an information disclosure vulnerability in D-Link DIR-X1860Z routers running firmware up to 1.0.2.220120.165402. The flaw resides in the routerd.wificfg_get and routerd.get_rand_key functions exposed through the ubus JSON-RPC interface. An unauthenticated attacker on the adjacent network can invoke these functions to retrieve sensitive router configuration data, including Wi-Fi settings and cryptographic key material. The vulnerability is classified under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor. D-Link has published a firmware hotfix, though the affected model is no longer under active vendor support.
Critical Impact
An adjacent-network attacker can extract Wi-Fi configuration and random key material from the router without authentication, enabling further network compromise.
Affected Products
- D-Link DIR-X1860Z firmware versions up to 1.0.2.220120.165402
- routerd service exposing the ubus JSON-RPC interface
- End-of-life D-Link consumer routers no longer receiving standard support
Discovery Timeline
- 2026-09-20 - CVE-2026-94050 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-94050
Vulnerability Analysis
The DIR-X1860Z exposes an OpenWrt-style ubus (micro bus) daemon that brokers JSON-RPC calls between local services and management interfaces. The routerd object registers two callable methods, wificfg_get and get_rand_key, that return sensitive configuration data without enforcing authentication or origin checks. An attacker on the local wireless or wired network can issue crafted JSON-RPC requests to the exposed endpoint and receive Wi-Fi configuration parameters and cryptographic key material in the response. Because the vulnerability requires only adjacent-network access and no user interaction, an attacker joined to the guest or LAN segment can retrieve secrets directly.
Root Cause
The root cause is missing access control on privileged ubus methods. The routerd service registers wificfg_get and get_rand_key without ACL enforcement, so any caller reachable through the JSON-RPC interface can invoke them. This design flaw maps to [CWE-200] because information intended for privileged management contexts is returned to unauthorized callers.
Attack Vector
Exploitation requires network adjacency, meaning the attacker must be connected to the same LAN or Wi-Fi segment as the router. No credentials are required. The attacker sends a JSON-RPC request to the ubus interface invoking routerd.wificfg_get or routerd.get_rand_key and parses the returned JSON payload for Wi-Fi SSIDs, passphrases, and derived key material. The disclosed data can then be used to persist on the wireless network or to attack downstream clients.
No verified proof-of-concept code is published in the enriched data. Refer to the D-Link Security Publication SAP10513 and VulDB CVE-2026-94050 entries for additional technical context.
Detection Methods for CVE-2026-94050
Indicators of Compromise
- Unexpected JSON-RPC requests to the router's ubus endpoint originating from LAN or Wi-Fi clients
- Repeated invocations of routerd.wificfg_get or routerd.get_rand_key in router service logs
- Rogue devices associating to the wireless network shortly after configuration data is queried
Detection Strategies
- Capture LAN traffic and inspect for HTTP POST bodies containing "method":"call" targeting routerd objects
- Correlate wireless client join events with subsequent authentication attempts using previously private credentials
- Baseline management-plane traffic and alert on non-administrator endpoints reaching the router's control interfaces
Monitoring Recommendations
- Enable syslog forwarding from the router to a central log store where ubus and routerd activity can be retained
- Monitor DHCP and ARP tables for unauthorized wireless clients that may be positioned to reach the JSON-RPC interface
- Track configuration changes and Wi-Fi credential rotations to detect misuse of leaked key material
How to Mitigate CVE-2026-94050
Immediate Actions Required
- Upgrade DIR-X1860Z firmware to version 1.0.7.260821.161908 using the vendor hotfix
- Rotate Wi-Fi passphrases and any pre-shared keys that may have been exposed through get_rand_key
- Restrict physical and wireless access to the LAN segment hosting affected routers
- Plan replacement of end-of-life D-Link hardware that no longer receives regular security maintenance
Patch Information
D-Link has released a hotfix that resolves the missing access control on the ubus JSON-RPC methods. Download the update from the D-Link Firmware Hotfix package and follow the instructions in the D-Link Security Publication SAP10513. The vendor notes that the DIR-X1860Z is no longer under standard support, so administrators should treat this hotfix as an interim measure and plan for hardware replacement.
Workarounds
- Segment untrusted wireless clients onto an isolated VLAN that cannot reach the router's management interface
- Disable guest Wi-Fi networks that share the same broadcast domain as the router control plane
- Enforce WPA3 or the strongest available authentication to reduce the population of adjacent-network attackers
# Example: isolate guest SSID from the management VLAN on an upstream switch
vlan 20 name GUEST_WIFI
interface vlan 20
ip access-group DENY_MGMT in
access-list DENY_MGMT deny ip any host 192.168.0.1
access-list DENY_MGMT permit ip any any
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
