CVE-2026-7554: D-Link m60 Firmware
High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized.
Affected products
- D-Link m60 Firmware: version 1.20b02 only
Published 2026-05-01. Last modified 2026-06-17.