• Home Support Forums Security Advisories Shop     English | French
Security Announcement
Announcement > SAP10513
(Non-US) DIR-X1860 / (Non-US) DIR-X1860Z : Unauthenticated Administrator Password Change and Access Control Vulnerability
Publication ID: SAP10513
Resolved Status: Yes
Published on: 26 August 2026 5:45 GMT
Last updated on: 26 August 2026 7:56 GMT

Overview

 

On August 18, 2026, D-Link Systems, Inc. (US) received a security report concerning the DIR-X1860Z, a non-US product, running firmware version V1.0.2.220120.165402.


The researcher reported that the device's OpenWrt-based ubus JSON-RPC management interface permits certain privileged routerd methods to be accessed without proper authentication.


The primary reported issue involves the routerd.passwd_set method. An unauthenticated user with access to the device's local network may be able to invoke this method to change the administrator password. The user could subsequently authenticate through the normal login process and obtain an authenticated administrative ubus_rpc_session.

 

The researcher also reported a related information-disclosure issue involving access to wireless configuration information through the ubus management interface.

 

After receiving the report, D-Link investigated the findings and developed updated firmware to mitigate the reported security issues.

 

The reported issues are addressed in: DIR-X1860Z Firmware V1.0.7.260821.161908

 

The firmware security update was finalized and updated on August 25, 2026.

 

The DIR-X1860Z remains an active product and users should update affected devices to the fixed firmware.

 

The similarly named DIR-X1860, all hardware revisions, has reached End of Life ("EOL") / End of Service Life ("EOS"). The DIR-X1860 and DIR-X1860Z have different product life-cycle status. This security announcement and firmware update apply specifically to the DIR-X1860Z.

 

The DIR-X1860Z is a non-US product and was not sold or supported by D-Link Systems, Inc. in the United States.

 

D-Link takes network security and user privacy seriously. D-Link maintains product-management and security-response resources to investigate reported security issues and provide appropriate product updates.

 

Report Information

 

Security Researcher: Lim Kar Joon
Original Report Received: August 18, 2026
Reported Product: DIR-X1860Z
Reported Hardware: A1 / V1.0
Reported Firmware: V1.0.2.220120.165402
Affected Component: ubus JSON-RPC management interface / routerd
Reported Interface: TCP port 23355 / /ubus
Vulnerability Classes: Improper Access Control / Improper Authorization and Information Disclosure
CVE Identifier: None assigned
Resolution Status: Resolved

 

Reported Vulnerabilities

 

Finding 1 — Unauthenticated Administrator Password Modification

 

CVE: None assigned

 

The researcher reported that the routerd.passwd_set method could be invoked without proper authentication through the device's ubus JSON-RPC management interface.

 

- Affected Method: routerd.passwd_set
- Component: ubus JSON-RPC / routerd management interface
- Access Requirement: Local network access
- Vulnerability Type: Improper Access Control / Improper Authorization
- Status: Resolved in firmware V1.0.7.260821.161908

 

An unauthenticated user with local network access could potentially use the affected interface to establish a new administrator password. The user could then authenticate normally and obtain an authenticated administrative ubus session.

 

Finding 2 — Wireless Configuration Information Disclosure

 

CVE: None assigned

 

The researcher reported a related condition involving unauthorized access to wireless configuration information through exposed routerd methods.

 

The report identified interaction between routerd.wificfg_get and routerd.get_rand_key as permitting recovery of wireless configuration information, including wireless credentials, under the reported firmware.

 

Affected Methods:

  • routerd.wificfg_get

  • routerd.get_rand_key

 

- Component: ubus JSON-RPC / routerd management interface
- Access Requirement: Local network access
- Vulnerability Type: Information Disclosure / Improper Access Control
- Status: Resolved in firmware V1.0.7.260821.161908

 

CVE, CWE, and CVSS Information

 

No CVE identifier has been assigned to these reported vulnerabilities as of the date of this publication.

 

D-Link has therefore not associated a public CVE, CWE assignment, or authoritative CVSS score with these findings in this announcement.

 

Affected Models

 

Model Hardware Revision Affected Software Version Region Fixed Release Last Updated
DIR-X1860 ALL All Non-US Model Not Available EOL/EOS 08/25/26
DIR-X1860Z A1 / V1.0 V1.0.2.220120.165402 Non-US / Global markets where distributed V1.0.7.260821.161908 08/25/26

 

Security Update for Your D-Link Device

 

Users with an affected DIR-X1860Z should install firmware version: V1.0.7.260821.161908 or a later firmware release when available.

 

Firmware file: DIR-X1860Z_V1.0.7.260821.161908_UPGRADE_ALL.bin

 

Firmware download: https://support.dlink.com/resource/SECURITY_ADVISEMENTS/DIR-X1860Z/DIR-X1860Z_REVA_FIRMWARE_V1.0.7.260821.161908_HOTFIX.zip

 

After installing the firmware, verify that the device's administration interface reports firmware version V1.0.7.260821.161908 or a later version.

 

The DIR-X1860Z is a non-US product. Product availability, support, and update procedures may vary by country or regional D-Link organization.

 

D-Link products may be produced in multiple hardware revisions. Firmware should only be installed on the applicable model and supported hardware revision.

 

Before installing the update:

 

Confirm that the product model is DIR-X1860Z.

- Confirm that the firmware is intended for the applicable DIR-X1860Z hardware revision.

- Download only firmware designated for the DIR-X1860Z.

- Follow the firmware-installation instructions provided by the applicable regional D-Link organization.

- Do not install DIR-X1860 firmware on a DIR-X1860Z or DIR-X1860Z firmware on a DIR-X1860.

 

The hardware revision is printed on the product label near the serial number and may also be displayed in the device's web-based administration interface.

 

DIR-X1860 Product Life-Cycle Notice

 

The DIR-X1860, all hardware revisions, has reached EOL/EOS.

 

As a general policy, when D-Link products reach EOL/EOS, resources associated with those products cease development and those products are no longer supported.

 

D-Link Systems, Inc. recommends retiring EOL/EOS products and replacing them with products that continue to receive firmware and security updates.

 

This EOL/EOS notice does not apply to the DIR-X1860Z, which remains an active product and is addressed by the firmware update documented in this security announcement.

 

Acknowledgment

 

D-Link thanks Lim Kar Joon for reporting these security issues and supporting the coordinated disclosure and resolution process.