D-Link DIR-X1860Z routers: local attacker can steal Wi-Fi passwords

Published August 31, 2026

A flaw in the D-Link DIR-X1860Z router lets someone on your home network reset your admin password and steal your Wi-Fi password if they have physical access to your router.

Report priority
Medium
Targets
DIR-X1860Z

How it works

Someone with physical access to your router can trick it into resetting its admin password and revealing your Wi-Fi password by exploiting a flaw in the router's login system.

What to do

Check the installed router firmware version. If it's V1.0.2.220120.165402 and you're outside the US, you're affected.

Update your router's firmware to the latest version available from D-Link's support site and verify the new version number matches the one listed there.

Technical details

Someone plugs a USB drive into your router's USB port. The router reads the drive and resets its admin password. Then the attacker logs in and copies your Wi-Fi password from the router's settings.

A local attacker on the same network as a D-Link DIR-X1860Z router (hardware revision A1/V1.0, running firmware V1.0.2.220120.165402) can exploit two flaws to reset the admin password and extract stored Wi-Fi credentials. The issue stems from insufficient authentication checks and improper handling of wireless configuration data. Researchers disclosed the vulnerabilities, prompting D-Link to release a fix. No CVE ID or CVSS score was assigned.