D-Link DIR-1253 MESH Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the D-Link DIR-1253 MESH router, specifically in version 1.6.1684. The issue arises from a hardcoded credential embedded within the etc/shadow.sample file, which is utilized by the device's boot scripts. This vulnerability could potentially be exploited by accessing the device's serial pin, leading to further attacks.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, potentially enabling an attacker to gain elevated rights on the device.

Reproduction

The vulnerability can be reproduced by accessing the etc/shadow.sample file, which contains hardcoded credentials. These credentials are used by the device's boot scripts, creating a window for privilege escalation. Once the credentials are extracted, they can be used to escalate privileges, for example, by accessing the device through its serial pin.

Added: Mar 5, 2026, 8:24 PM
Updated: Mar 5, 2026, 8:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
0.0
relevance
3.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.