← All Advisories

CVE-2026-95675

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-95675

Key Details

CVECVE-2026-95675
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsD-Link DAP-1360
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
D-LinkDAP-1360
SubsystemsGeneral OT
SectorsMultiple

What to Know

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network. (NVD)

What to Do

Monitor D-Link's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-95675
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-95675