CVE-2026-94050Medium· 4.3▾ SunlitA vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure.…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to version 1.0.7.260821.161908 is able to address this issue. It is suggested to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94036High· 8.8A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402
CVE-2026-90881Medium· 5.3A weakness has been identified in D-Link DIR-882 up to 20260814
CVE-2026-94089Critical· 10.0A vulnerability was determined in D-Link DIR-868L 2.01b05
CVE-2026-93958Critical· 9.1A vulnerability was found in D-Link R95 BE9500_1.00.16
CVE-2026-91003Critical· 9.1A flaw has been found in D-Link DI-8300 16.07
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.07