CVE-2026-94036 is an improper access-control vulnerability in the routerd component of D-Link DIR-X1860 and DIR-X1860Z routers running firmware through version 1.0.2.220120.165402. An unspecified routerd management function insufficiently enforces authorization when processing the passwd_set argument, allowing an unauthenticated adjacent-network attacker to invoke unauthorized functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository consists solely of poc.py, a standalone Python 3 proof-of-concept targeting D-Link DIR-X1860 and DIR-X1860Z routers. It communicates with the router's HTTP-exposed UBUS JSON-RPC interface and relies on a hard-coded all-zero session token that vulnerable firmware incorrectly authorizes for sensitive routerd operations. The script implements three subcommands: verify uses session.access as an ACL oracle to enumerate exposed methods; psk retrieves wireless configuration and unauthenticated AES key material to decrypt stored WPA passwords; and takeover changes the admin password, authenticates as the new admin, and prints privileged device and WAN configuration. The optional factory-reset action is destructive. AES-CBC encryption follows the firmware scheme, including the fixed IV SafeKey@netis.cn and per-request key material obtained from routerd.get_rand_key. The target URL is configurable with --url, but defaults to http://192.168.0.1:23355/ubus.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper access-control vulnerability in the routerd component's /ubus functionality on D-Link DIR-X1860 and DIR-X1860Z routers through firmware version 1.0.2.220120.165402. Manipulating the passwd_set argument can enable unauthorized access from the local network.
An improper access-control vulnerability in the routerd component's /ubus interface on D-Link DIR-X1860 and DIR-X1860Z routers through firmware version 1.0.2.220120.165402. An unauthenticated attacker on the local network can manipulate the passwd_set argument, potentially compromising confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.