CVE-2022-50596: D-Link Dir-1260 Firmware
Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.
D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within the SetDest/Dest/Target arguments to the GetDeviceSettings form. The management interface is accessible over HTTP and HTTPS on the local and Wi-Fi networks and optionally from the Internet.
Affected products
- D-Link Dir-1260 Firmware: up to and including 1.20b05
Published 2025-11-06. Last modified 2026-06-17.