TL;DR
D-Link has released a critical security update for its DIR-X1860Z routers. This update addresses severe unauthenticated access flaws in the management interface. The newly discovered DIR-X1860Z vulnerability allows local network attackers to change the administrator password. Attackers can also access sensitive wireless configuration data. Users must update their firmware to version V1.0.7.260821.161908 immediately.
Why the Vulnerability Matters
A successful exploit gives attackers full administrative control over the router. Consequently, they can compromise the entire local network. Attackers can easily reroute traffic, intercept sensitive data, and expose Wi-Fi credentials. D-Link has not published specific estimates for affected installation counts. Furthermore, researchers have not confirmed any active exploitation in the wild. Additionally, no public proof-of-concept currently exists for this exploit. However, this flaw joins a concerning history of router security defects. Past examples include CVE-2021-41441, CVE-2021-41442, and CVE-2021-41445. Therefore, administrators must treat this update as a high priority.
How the Attack Works
The DIR-X1860Z vulnerability resides in the OpenWrt-based ubus JSON-RPC management interface. Specifically, the interface fails to enforce proper authentication checks. This failure affects certain privileged routerd methods. An attacker on the local network can invoke the routerd.passwd_set method. They can do this without supplying any valid credentials. Therefore, they can easily overwrite the administrator password. Next, the attacker logs in normally to gain an authenticated administrative session. Additionally, the attacker can call routerd.wificfg_get and routerd.get_rand_key. These functions allow the attacker to extract plaintext wireless configuration details.
Affected Versions and Hardware
This flaw specifically impacts the non-US D-Link DIR-X1860Z model. It affects Hardware Revision A1 running firmware V1.0.2.220120.165402. The similarly named DIR-X1860 model recently reached its End of Life and End of Service Life phase. As a result, that older model receives no further security updates. This security announcement applies exclusively to the DIR-X1860Z. D-Link did not sell or support the DIR-X1860Z inside the United States.
Patch and Mitigation Steps
D-Link has released a hotfix to resolve these improper access control issues. Administrators should download and install firmware version V1.0.7.260821.161908. You can find the update files and upgrade instructions in the official D-Link security advisory. First, confirm your exact hardware revision on the product label. Next, download only the firmware designated for the DIR-X1860Z. Finally, verify the installed version through the web administration interface. Do this verification immediately after the upgrade completes. This ensures your network remains protected against unauthorized access.