{"id":"CVE-2026-95675","published":"2026-09-22T14:17:22.230","lastModified":"2026-09-22T20:25:55.870","description":"D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10451","tags":[]},{"url":"https://www.d6fault.dev/blog/dlink-dap1360-os-command-injection","tags":[]},{"url":"https://www.vulncheck.com/advisories/d-link-dap-1360-unauthenticated-rce-via-web-management-interface","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an unauthenticated remote code execution vulnerability in D-Link DAP-1360 firmware versions 6.14 and earlier, allowing attackers to execute arbitrary commands as root via crafted web requests. This vulnerability is critical as it enables full device compromise and potential network pivoting.","exploitability":"Exploitation is relatively straightforward as it requires no valid credentials and can be performed by sending crafted requests to the device's web management interface. Precondition is access to the device's web interface.","blast_radius":"If exploited, the vulnerability could lead to full device compromise, persistent configuration modification, and use of the device as a pivot point into the local network, posing a significant risk to the network's security.","remediation":"Upgrade to firmware version 6.15 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","unauth","critical"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:23.381Z"}}