LonTan0

2 exploits Active since Aug 2025
CVE-2026-2163 WRITEUP MEDIUM WORKING POC
Dlink Dir-600 Firmware < 2.15wwb02 - Command Injection
A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS 4.7
CVE-2025-8956 WRITEUP MEDIUM WORKING POC
Dlink Dir-818l Firmware - Command Injection
A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS 6.3