chiprook
← Security
SecurityOctober 7, 2026, 11:20

CVE-2026-95675: Unauthenticated root RCE in D-Link DAP-1360

A critical OS command injection (CVSS 9.8) in the D-Link DAP-1360 web interface lets unauthenticated attackers run commands as root via the ipv4 ping parameter in apply.cgi. D-Link retired the device in August 2020 and will not issue a fix; 423 exposed instances were found online.

CVE-2026-95675: Unauthenticated root RCE in D-Link DAP-1360
#D-Link
Read next
Security

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root

Security

F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE that hardening won't stop

Security

WordPress Click2Shell: unauthenticated RCE, fixed in 7.1.1

Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws