CVE-2026-95675
9.8 CRITICALPublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw is an unauthenticated remote code execution vulnerability in D-Link DAP-1360 firmware versions 6.14 and earlier, allowing attackers to execute arbitrary commands as root via crafted web requests. This vulnerability is critical as it enables full device compromise and potential network pivoting.
- Exploitability
- Exploitation is relatively straightforward as it requires no valid credentials and can be performed by sending crafted requests to the device's web management interface. Precondition is access to the device's web interface.
- Blast radius
- If exploited, the vulnerability could lead to full device compromise, persistent configuration modification, and use of the device as a pivot point into the local network, posing a significant risk to the network's security.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to firmware version 6.15 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-12342
- CRITICALCVE-2026-13249
- CRITICALCVE-2023-54399
- CRITICALCVE-2026-102304
- CRITICALCVE-2026-102316
- CRITICALCVE-2026-102331
- HIGHCVE-2026-18895PoC
- CRITICALCVE-2026-28324
Related by shared AI tags and CWE weakness class. Browse the full archive.