D-LINK has issued a critical security update for its DIR-X1860Z routers, addressing serious security vulnerabilities that allow unauthenticated access to the management interface. Attackers on a local network could exploit these flaws to change the administrator password and access sensitive configuration data. Users are urged to update to firmware version V1.0.7.260821.161908 promptly.
The vulnerability is linked to improper authentication in the OpenWrt-based ubus JSON-RPC interface, impacting only the non-US model of the DIR-X1860Z. Although no active exploits have been reported, the case highlights ongoing concerns regarding router security.