CVE-2026-95675: Unauthenticated root RCE in D-Link DAP-1360
A critical OS command injection (CVSS 9.8) in the D-Link DAP-1360 web interface lets unauthenticated attackers run commands as root via the ipv4 ping parameter in apply.cgi. D-Link retired the device in August 2020 and will not issue a fix; 423 exposed instances were found online.
- CVSS v3 score is 9.8; public exploit code and analysis are available
- All DAP-1360 hardware revisions on firmware 6.14 and earlier are affected
- No patch planned: vendor ended support for the product in August 2020
- ZoomEye found 423 DAP-1360 instances exposed to the internet
Read next
Security