
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has patched two local-network vulnerabilities in its non-US DIR-X1860Z router that could allow an unauthenticated attacker to replace the administrator password and recover Wi-Fi configuration data, including wireless credentials. The issues affect hardware revision A1/V1.0 running firmware V1.0.2.220120.165402 and stem from insufficient authentication controls in the device’s OpenWrt-based ubus JSON-RPC management interface. The primary […]
The post D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft appeared first on Cyber Security News.