important · Wi-Fi
A pre-authentication web request executes commands as root on D-Link DAP-1360 access points.
Affects
D-Link DAP-1360 wireless access points running embedded router firmware.
The formSystemCheck handler places the ipv4_ping parameter into a shell command without neutralizing separators. The public request-level proof of concept produced uid 0 on an emulated extracted firmware image.
Detail and 4 sources
D-Link classifies the line as end-of-life and recommends replacement rather than providing a patch.
Sources
ResearchD6fault | OS Command Injection in D-Link DAP-1360 formSystemCheck HandlerResearchD-Link: PoC pubblico per lo sfruttamento della CVE-2026-95675 (AL09/260923/CSIRT-ITA) – CSIRT ToscanaVendorD-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface | Advisories | VulnCheckVendorD-Link Technical Support