CSIRT-ITA warned that a public proof of concept exists for CVE-2026-95675 in the D-Link DAP-1360 web management interface, a remote code execution flaw rated CVSS 9.3. D-Link says the device is end-of-life, so there is no vendor patch or workaround to apply.
The bug is an input-validation failure: a remote, unauthenticated attacker can send crafted HTTP requests to the admin page and get commands executed as root. That can fully compromise the device, let an attacker alter its configuration persistently, and turn it into an access point for further activity on the local network.
For any team still running these units, the exposure sits at the management plane, not just on the box itself. If the interface is reachable from the WAN, a public PoC makes the device an immediately exploitable foothold, and remediation burden stays with the asset owner because the vendor will not ship a fix.
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.