Critical D-Link Router Flaws Let Attackers Change Admin Password, Steal Wi-Fi Credentials
Key Takeaways Two critical vulnerabilities in D-Link’s DIR-X1860Z router (hardware revision A1, firmware V1.0.2.220120.165402) allow local network attackers to seize control. Attackers can...
Key Takeaways
- Two critical vulnerabilities in D-Link’s DIR-X1860Z router (hardware revision A1, firmware V1.0.2.220120.165402) allow local network attackers to seize control.
- Attackers can change the administrator password and steal Wi-Fi credentials due to improper access control and information disclosure flaws.
- The issues affect the router’s OpenWrt-based ubus JSON-RPC management interface, exposed on TCP port 23355.
- D-Link has released firmware version V1.0.7.260821.161908 to patch these vulnerabilities.
- Users of the affected DIR-X1860Z model are strongly advised to update immediately. The DIR-X1860, a separate model, is end-of-life and will not receive patches.
D-Link has rolled out a crucial firmware update addressing significant access control and information disclosure flaws present in its DIR-X1860Z router. These vulnerabilities could empower an unauthenticated attacker, operating within the local network, to completely reset the router’s administrator password and extract sensitive wireless configuration data, including Wi-Fi network credentials.
Table Of Content
Details of these security issues were made public in D-Link’s advisory SAP10513, released on August 26, 2026. The company acknowledged receiving the initial vulnerability report from security researcher Lim Kar Joon on August 18, 2026.
The specific product impacted is the non-US D-Link DIR-X1860Z, specifically hardware revision A1 running firmware V1.0.2.220120.165402. These security weaknesses are rooted in the router’s OpenWrt-based ubus JSON-RPC management interface.
This critical interface is accessible via TCP port 23355 at the /ubus endpoint, where the device’s routerd service manages privileged router operations. The first identified flaw centers on the routerd.passwd_set method.
D-Link Router Flaws Detailed
According to D-Link, the routerd.passwd_set method could be invoked without proper authentication on the vulnerable firmware versions. This allows an attacker, already connected to the victim’s local network, to establish a new administrator password for the router. Once the password is changed, the attacker can then use standard router login procedures to gain an authenticated administrative ubus session.
This administrative access grants the attacker full control over the device’s management functions. They could then alter router settings, modify network services, change access rules for connected devices, and make other significant administrative configurations.
The second vulnerability is an information disclosure flaw within the same ubus management interface. D-Link stated that exposed routerd methods could permit unauthorized users to retrieve critical wireless configuration details. Specifically, the affected functions are routerd.wificfg_get and routerd.get_rand_key. By exploiting these methods, an attacker on the local network could potentially recover Wi-Fi configuration data, including the network’s wireless credentials. The theft of Wi-Fi passwords could enable an attacker to maintain persistent access to the network, reconnect at will, or distribute the credentials to other unauthorized parties.
D-Link categorized these findings as improper access control, improper authorization, and information disclosure. At the time of this publication, no specific CVE identifier, CWE classification, or official CVSS severity score has been assigned to these vulnerabilities.
Both issues have been addressed by D-Link in DIR-X1860Z firmware version V1.0.7.260821.161908. The security update was finalized on August 25, 2026, and D-Link strongly advises all affected users to install this patched release or any subsequent versions as they become available.
Administrators must first verify that their router is indeed the DIR-X1860Z model and confirm the applicable hardware revision before proceeding with the update. D-Link issued a critical warning: users should never install DIR-X1860 firmware on a DIR-X1860Z device, or vice-versa, as this could lead to device malfunction. The similarly named DIR-X1860 is a distinct, non-US product that has reached its end-of-life and end-of-service status. D-Link confirmed that the DIR-X1860 will no longer receive security updates and recommends that users retire or replace it with a currently supported router. This specific security update exclusively applies to the actively supported DIR-X1860Z product.
What You Should Do
- Verify Your Model: Confirm your router is the D-Link DIR-X1860Z (hardware revision A1). Do not confuse it with the DIR-X1860.
- Check Current Firmware: Identify your router’s current firmware version. If it is V1.0.2.220120.165402 or older, you are vulnerable.
- Update Firmware Immediately: Download and install firmware version V1.0.7.260821.161908 or any newer available version from the official D-Link support website.
- Regularly Monitor D-Link Advisories: Stay informed about future security announcements and updates from D-Link.
- Consider Router Replacement (DIR-X1860 users): If you own a D-Link DIR-X1860, be aware it is end-of-life and unsupported; consider replacing it with a current, supported model.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.