A vulnerability, which was classified as critical, has been found in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery.

This vulnerability is handled as CVE-2026-7554. The attack can be initiated remotely. Additionally, an exploit exists.