Impact
A security flaw is present in the routerd component of D-Link DIR‑X1860 and DIR‑X1860Z devices, where the passwd_set argument of the /ubus file can be manipulated to bypass the intended access controls. This defect permits an attacker on the local network to alter the router’s administrative password or potentially inject unauthorized commands, effectively allowing the attacker to gain control over the device. The vulnerability stems from improper validation of the passwd_set parameter, identified as CWE‑266 and CWE‑284.
Affected Systems
Devices affected are the D-Link DIR‑X1860 and DIR‑X1860Z routers with firmware versions up to 1.0.2.220120.165402. The issue resides in the routerd component accessed through the /ubus interface, which controls administrative credentials.
Risk and Exploitability
The CVSS score of 8.7 classifies this defect as high severity. The EPSS score is currently unavailable, yet the vulnerability is publicly disclosed and exploits have been released. It has not yet appeared in CISA’s KEV catalog, but the local‑network requirement means that anyone with LAN access can exploit the flaw, potentially compromising the router’s configuration and any connected devices.
OpenCVE Enrichment