Skip to main content
Vulnerability Database/CVE-2026-95675

CVE-2026-95675: D-Link DAP-1360 RCE Vulnerability

CVE-2026-95675 is an unauthenticated remote code execution flaw in D-Link DAP-1360 firmware 6.14 and earlier that lets attackers execute commands as root. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-95675 Overview

CVE-2026-95675 is an unauthenticated remote code execution vulnerability affecting D-Link DAP-1360 wireless access points running firmware version 6.14 and earlier. The flaw allows a remote attacker to execute arbitrary operating system commands as root by sending crafted HTTP requests to the device's web management interface without any valid credentials. Successful exploitation grants full device control, enabling persistent configuration changes and lateral movement into the connected local network. The vulnerability is classified as OS Command Injection [CWE-78] and carries a CVSS 4.0 base score of 9.3.

Critical Impact

Unauthenticated attackers can obtain root-level command execution on affected DAP-1360 devices and pivot into internal networks.

Affected Products

  • D-Link DAP-1360 wireless range extender / access point
  • Firmware version 6.14
  • All prior firmware releases in the 6.x branch

Discovery Timeline

  • 2026-09-22 - CVE-2026-95675 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95675

Vulnerability Analysis

The vulnerability resides in the DAP-1360 web management interface, which processes HTTP request parameters and passes attacker-controlled input directly to underlying shell command execution routines. Because the affected endpoints do not require authentication, any attacker with network reachability to the device's management interface can trigger the flaw. The injected commands run in the context of the root user, giving the attacker complete control over the embedded Linux operating system.

An attacker who compromises the device can modify firmware behavior, alter DNS and routing configuration, capture wireless traffic, and use the device as a persistent foothold. The DAP-1360 typically sits inside trusted network segments, so a compromised unit is well positioned for pivoting into adjacent hosts. See the VulnCheck Advisory on DAP-1360 RCE and the D6Fault Blog on DAP-1360 Exploit for technical write-ups.

Root Cause

The root cause is improper neutralization of special elements used in an OS command [CWE-78]. The web interface concatenates user-supplied request parameters into shell command strings without validation, sanitization, or safe API usage. Shell metacharacters such as ;, |, and backticks are interpreted by the underlying shell, enabling arbitrary command execution.

Attack Vector

Exploitation requires only network access to the DAP-1360 management interface, typically exposed on TCP port 80 or 443. The attacker sends a crafted HTTP request to a vulnerable endpoint with injected shell metacharacters in a parameter value. The device parses the request, invokes the affected handler, and executes the attacker-controlled commands as root. No user interaction, prior authentication, or elevated privileges are required.

No verified exploit code is currently published. Refer to the D-Link Security Advisory SAP10451 for vendor-confirmed details.

Detection Methods for CVE-2026-95675

Indicators of Compromise

  • Unexpected outbound connections originating from the DAP-1360 to external IP addresses or unusual ports.
  • Unauthorized configuration changes, new administrative accounts, or altered DNS server entries on the device.
  • HTTP requests to the management interface containing shell metacharacters such as ;, |, &, or $( in query parameters or POST bodies.
  • Presence of unfamiliar processes, cron entries, or startup scripts on the device if shell access is available.

Detection Strategies

  • Inspect network traffic to and from DAP-1360 management interfaces for anomalous HTTP request patterns and injection payloads.
  • Correlate wireless infrastructure device logs with adjacent host telemetry to identify pivoting activity originating from the access point.
  • Alert on any administrative changes to DAP-1360 devices that occur outside approved change windows.

Monitoring Recommendations

  • Place DAP-1360 devices on a dedicated management VLAN and monitor east-west traffic for lateral movement attempts.
  • Log and centrally review all authentication attempts and configuration change events from network infrastructure.
  • Continuously scan the environment for DAP-1360 devices exposing their web management interface to untrusted networks.

How to Mitigate CVE-2026-95675

Immediate Actions Required

  • Restrict access to the DAP-1360 web management interface to trusted management networks only, using firewall or ACL controls.
  • Disable remote (WAN-side) management on all DAP-1360 devices until a fixed firmware version is applied.
  • Inventory all DAP-1360 units in the environment and confirm firmware versions against the vendor advisory.
  • Rotate any credentials, pre-shared keys, and certificates that may have been exposed on compromised devices.

Patch Information

Consult the D-Link Security Advisory SAP10451 for vendor guidance, supported firmware updates, and end-of-life status for the DAP-1360. Apply the vendor-supplied firmware update as soon as it is available for the affected hardware revision. Where the device is designated end-of-life without a patch, plan replacement with a supported model.

Workarounds

  • Segment DAP-1360 devices onto an isolated network with no direct routing to sensitive internal systems.
  • Block inbound HTTP and HTTPS traffic to the device management interface from all untrusted sources at the perimeter and internal firewalls.
  • Where feasible, decommission affected devices and replace them with currently supported hardware that receives security updates.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.