Impact
A flaw in the web management interface of the D-Link DAP-1360 allows an attacker to send specially crafted HTTP requests without authentication and execute arbitrary shell commands as the root user. This results in full compromise of the device, enabling persistent configuration changes and the potential to act as an entry point for further attacks within the local network.
Affected Systems
The vulnerability affects D-Link DAP-1360 Wi‑Fi access points running firmware version 6.14 or earlier. Devices with this firmware can be remotely accessed via the web interface from any host on the same network segment.
Risk and Exploitability
The severity of the CVSS score 9.3 indicates a critical impact. While no EPSS score is provided, the absence of a KEV listing suggests that widespread exploitation has not yet been observed, but the high score and unauthenticated nature mean the risk is still high. Attackers need only network connectivity to the device’s management port; no valid credentials are required, so a remote attacker on the local or transit network can exploit the flaw without further reconnaissance.
OpenCVE Enrichment