Impact
An attacker who can reach the ubus JSON‑RPC endpoint on a D‑Link DIR‑X1860Z router can invoke the routerd.get_rand_key function. This function returns a random key that is normally protected from external observation. The resulting disclosure allows an attacker to learn sensitive information that was meant to be private. The weakness is a classic information disclosure flaw (CWE‑200) coupled with an improper authorization check (CWE‑284), enabling the operation without proper privileges.
Affected Systems
The vulnerability affects all DIR‑X1860Z units running firmware versions up to and including 1.0.2.220120.165402. The vendor recommends installing firmware 1.0.7.260821.161908 or later to remediate the issue. No other D‑Link products were mentioned as affected.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered medium severity. The exploitation requires local network access to send JSON‑RPC calls to the ubus interface; remote exploitation is not feasible as described. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, indicating no documented use in the wild. Attacks would most likely be performed by an adversary who has compromised or positioned within the same local network as the router.
OpenCVE Enrichment