CVE-2026-95675: Unauthenticated Root Command Injection in D-Link DAP-1360 Firmware
Vulnerability overview
CVE-2026-95675 is a critical OS command injection flaw in the web management interface of the D-Link DAP-1360, a long-retired wireless access point and range extender. The vulnerability is rated Critical, with a reported CVSS v3 score of 9.8. Public technical analysis and working exploit code are available. D-Link has confirmed that it will not release a fix.
Mechanism and exploitation conditions
The defect lives in the device's web server binary rather than in a plugin or optional service. The network diagnostic handler behind apply.cgi reads a value from the ipv4 ping parameter, formats it into a system ping command, and hands the resulting string to the command interpreter without sanitising it.
Because the string is never escaped, an attacker can append shell metacharacters. The interpreter then treats the trailing text as additional commands. The endpoint performs no authentication check, so no credentials, session, or prior access to the administrative UI is required. Commands execute with root privileges, which is the highest privilege level on the appliance.
Impact
Successful exploitation gives an unauthenticated remote attacker full command execution as root through the management interface. From there an attacker can read and rewrite device configuration, alter routing or wireless settings, and install a persistent foothold that survives reboots. A compromised access point is an attractive pivot point: it sits inside the network perimeter, it is usually trusted, and it is rarely monitored as closely as a server.
Affected products and scope
All hardware revisions of the D-Link DAP-1360 running firmware version 6.14 and earlier are affected. D-Link formally retired the DAP-1360 product family in August 2020, and the vendor states that all firmware development for the product has ceased. There will be no patched release.
Exposure context
A ZoomEye search for the product fingerprint app="D-Link DAP-1360" returned 423 matching instances worldwide at the time of writing. A CVE-scoped query, vul.cve="CVE-2026-95675", returned no indexed assets, which is expected for a freshly assigned identifier. The product fingerprint therefore gives the more useful exposure estimate, and it only counts assets that still answer with a recognisable DAP-1360 signature; devices hidden behind firewalls or with a modified management banner are not represented.
Remediation and mitigations
There is no firmware fix and none is planned. The only complete remediation is replacement with supported hardware.
Where replacement cannot happen immediately, apply compensating controls: block access to the device's web management interface from untrusted networks, place the management UI on a dedicated VLAN restricted to trusted administrators, and treat any DAP-1360 as a potentially compromised asset if it has ever been reachable from an untrusted network. Inventory the installed base, confirm which units still carry firmware 6.14 or older, and prioritise their removal.
References
- D-Link DAP-1360 vulnerability details and PoC
- D-Link product security advisory for the retired DAP-1360 family
Top comments (0)