CVE-2026-95675
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| D-LINK | DAP-1360 | 0 <= 6.14 | affected |
Weaknesses
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: total
References
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10451
- https://www.d6fault.dev/blog/dlink-dap1360-os-command-injection
- https://www.vulncheck.com/advisories/d-link-dap-1360-unauthenticated-rce-via-web-management-interface
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.