TL;DR
Security researchers published technical details and a functional exploit for a critical D-Link DAP-1360 vulnerability. Tracked as CVE-2026-95675, this flaw allows unauthenticated attackers to execute operating system commands as root. Network administrators must decommission affected devices immediately because no security patches will be released.
- CVE: CVE-2026-95675
- CVSS: 9.8 (Critical · CVSSv3)
- Product: D-LINK DAP-1360
- Affected: ≤ 6.14
- Impact: D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Track every D-Link CVE the moment it's exploited.
Get free email alertsWhy It Matters
This security flaw carries a critical CVSS score of 9.3. Telemetry suggests that thousands of legacy access points remain in operation globally. An attacker on the local network can take full control of the device without credentials. Fortunately, security teams have confirmed no active exploitation in the wild so far. However, technical analysis and working proof-of-concept exploit code are now publicly accessible. In an independent technical write-up, researchers published exploit details for the DAP-1360 flaw. Consequently, malicious actors can easily weaponize this issue to compromise internal networks.
How The Attack Works
The flaw stems from an unsafe command execution routine in the web server binary. Specifically, the system check handler at apply.cgi processes network diagnostic requests. The code extracts the ipv4 ping parameter and formats a system ping command without sanitization. Then, the server passes the unchecked string directly to the command interpreter. Because this endpoint requires no authentication, an attacker can append shell metacharacters. This action yields arbitrary command execution with root privileges. Attackers can then alter device configurations and establish persistent network footholds.
Affected Versions
The defect impacts D-Link DAP-1360 devices running firmware version 6.14 and earlier across all hardware revisions. The vendor officially retired the DAP-1360 product family in August 2020.
Patch Or Mitigation Steps
D-Link will not issue any software updates for this product. In an official security advisory, the company noted that “all firmware development for these products cease.” The vendor added, “D-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it.” Organizations must replace these end-of-life devices with supported hardware. If replacement is delayed, isolate the administrative interface from untrusted networks immediately. Addressing this D-Link DAP-1360 vulnerability prevents intruders from pivoting across enterprise environments.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!