Command Injection in Legacy CPE: A Technical Walkthrough of CVE-2026-95675
Overview
CVE-2026-95675 is a textbook command injection in consumer-grade customer premises equipment. The affected product is the D-Link DAP-1360, a wireless access point and range extender that the vendor retired in August 2020. Affected firmware is 6.14 and earlier across all hardware revisions. The flaw is unauthenticated and grants root-level command execution.
Where the flaw sits
The vulnerable code is in the device's web server binary, in the network diagnostic path. The handler behind apply.cgi accepts a ping target through the ipv4 ping parameter. It formats that value into a system ping command and passes the composed string to the command interpreter.
The problem is structural: the parameter is treated as trusted input. No escaping, no allow-listing, no shell-free invocation.
How exploitation works
An attacker sends a request to the diagnostic endpoint with a ping target that contains shell metacharacters. The interpreter splits the string and executes the attacker's trailing commands alongside the intended ping. Because the endpoint is unauthenticated, the request needs nothing more than network reachability to the management interface.
Commands run as root. That privilege on an embedded appliance is effectively total: the attacker can alter configuration, change wireless parameters, and write persistence that survives a reboot.
Why it is rated critical
The combination of unauthenticated access, remote triggerability, and root-level impact explains the critical rating and the reported CVSS v3 score of 9.8. There is no user interaction and no prerequisite beyond reachability.
Affected products and scope
D-Link DAP-1360, all hardware revisions, firmware 6.14 and earlier. No patched firmware will be produced; the vendor states that firmware development for the retired family has ceased and recommends retiring the product.
Exposure context
A ZoomEye search for the product fingerprint app="D-Link DAP-1360" returned 423 matching instances worldwide at the time of writing. A CVE-scoped query, vul.cve="CVE-2026-95675", returned no indexed assets, which is expected for a freshly assigned identifier. The product fingerprint therefore gives the more useful exposure estimate, and it only counts assets that still answer with a recognisable DAP-1360 signature; devices hidden behind firewalls or with a modified management banner are not represented.
Remediation
There is no software fix. Replace the device, or in the interim isolate its management interface from untrusted networks and treat internet-reachable units as compromised.
References
- D-Link DAP-1360 vulnerability details and PoC
- D-Link product security advisory for the retired DAP-1360 family
Top comments (0)