Vulnerabilities & Exploits · Web App Attack

D-Link DAP-1360’s RCE Leaves No Patch Path

CSIRT-ITA warned that a public proof of concept exists for CVE-2026-95675 in the D-Link DAP-1360 web management interface, a remote code execution flaw rated CVSS 9.3. D-Link says the device is end-of-life, so there is no vendor patch or workaround to apply.

The bug is an input-validation failure: a remote, unauthenticated attacker can send crafted HTTP requests to the admin page and get commands executed as root. That can fully compromise the device, let an attacker alter its configuration persistently, and turn it into an access point for further activity on the local network.

For any team still running these units, the exposure sits at the management plane, not just on the box itself. If the interface is reachable from the WAN, a public PoC makes the device an immediately exploitable foothold, and remediation burden stays with the asset owner because the vendor will not ship a fix.

2 sources · 5h ago

CVE-2026-86296

NVD KEV

CVSS 10 CRITICAL: a vulnerability was determined in D-Link DIR-822A A_101. EPSS 1% (70th percentile).

CVE-2026-94036

NVD KEV

CVSS 8.8 HIGH: a security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402.

CVE-2026-94050

NVD KEV

CVSS 4.3 MEDIUM: a vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402.

Timeline

Sources

Part of the PlainSec briefing for 2026-09-23

Every edition of this story: D-Link DAP-1360’s RCE Leaves No Patch Path

More from today