---
id: CVE-2026-95675
title: >-
  D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated
  remote code execution vulnerability that allows remote attackers to execute
  arbitrary commands as root by sending crafted requests to the device's web
  manageme…
summary: >-
  D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated
  remote code execution vulnerability that allows remote attackers to execute
  arbitrary commands as root by sending crafted requests to the device's web
  manageme…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: D-LINK
product: DAP-1360
affected:
  - DAP-1360 <= 6.14
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:25:55.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95675'
references:
  - url: >-
      https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10451
    label: disclosure@vulncheck.com
  - url: 'https://www.d6fault.dev/blog/dlink-dap1360-os-command-injection'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/d-link-dap-1360-unauthenticated-rce-via-web-management-interface
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-22T17:19:55.227926Z'
ingestedAt: '2026-09-22T14:04:19.588Z'
epss: 0.0391
epssPercentile: 0.8989
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/d6fault/CVE-2026-95675'
  checkedAt: '2026-09-25T08:21:25.970Z'
---

## Overview

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
