Skip to finding
important · Wi-Fi

A pre-authentication web request executes commands as root on D-Link DAP-1360 access points.

Affects

D-Link DAP-1360 wireless access points running embedded router firmware.

The formSystemCheck handler places the ipv4_ping parameter into a shell command without neutralizing separators. The public request-level proof of concept produced uid 0 on an emulated extracted firmware image.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026