CVE-2026-94050
Received Received - Intake

Information Disclosure in D-Link DIR-X1860Z Router

Vulnerability report for CVE-2026-94050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: VulDB

Description

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to version 1.0.7.260821.161908 is able to address this issue. It is suggested to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
d-link dir-x1860z to 1.0.2.220120.165402 (inc)
d-link dir-x1860z 1.0.7.260821.161908

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in D-Link DIR-X1860Z routers up to version 1.0.2.220120.165402. It exists in the routerd.wificfg_get and routerd.get_rand_key functions of the ubus JSON-RPC interface. An attacker within the local network can exploit this to access sensitive information.

Detection Guidance

This vulnerability affects D-Link DIR-X1860Z routers running firmware up to 1.0.2.220120.165402. Detection requires checking the router's firmware version via the admin interface or SSH. No specific commands are provided in the context, but you can verify the version through the web UI or CLI.

Impact Analysis

The vulnerability allows an attacker on the same local network to disclose confidential information from the router. This could include network credentials, connected device details, or other sensitive data. Since the product is no longer supported, no official patches are available.

Mitigation Strategies

Upgrade the router's firmware to version 1.0.7.260821.161908 or later. Since the product is no longer supported, consider replacing the device if an update is unavailable. Ensure the router is not exposed to untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart