Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-95675: D-Link DAP-1360 lets attackers run code remotely
CVE-2026-95675 · published 18 days ago
Summary
The D-Link DAP-1360 wireless access point (firmware 6.14 or earlier) can be taken over by anyone on the internet who sends specially crafted web requests, without needing a login. An attacker could gain full control of the device, change its settings and use it to reach other systems on your network. Update the firmware to the latest version or disable the web management interface until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dap-1360 | <= 6.14 |
Original advisory text
D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-78OS Command Injection
Timeline
Published22 Sep 2026
Updated9 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta