D-Link Router Flaws Let Unauthenticated Attackers Change Admin Password and Steal Wi-Fi Credentials
Brief
D-Link has released a firmware update for critical access-control and information-disclosure flaws affecting its DIR-X1860Z router.
The vulnerabilities could allow an unauthenticated attacker connected to the local network to change the router administrator password and recover wireless configuration details, including Wi-Fi credentials .
The security issues were disclosed in D-Link advisory SAP10513, published on August 26, 2026. The company said it received the original report from security researcher Lim Kar Joon on August 18, 2026.
The affected product is the non-US D-Link DIR-X1860Z, hardware revision A1 running firmware V1.
- 2.
- 165402. The vulnerabilities exist in the router’s OpenWrt-based ubus JSON-RPC management interface.
