EIP-2026-101010

PRE-CVE

D-Link DNS-320 ShareCenter - Remote Reboot/Shutdown/Reset (Denial of Service)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101010. PoCs published by rigan.

AI-analyzed exploit summary This Perl script exploits multiple unauthenticated DoS vulnerabilities in D-Link DNS-320 devices by sending crafted POST requests to various CGI endpoints, triggering reboot, shutdown, or factory reset. The exploit uses LWP::UserAgent to repeatedly send requests in an infinite loop.

Description

D-Link DNS-320 ShareCenter - Remote Reboot/Shutdown/Reset (Denial of Service)

Exploits (1)

exploitdb WORKING POC
by rigan · perldoshardware
https://www.exploit-db.com/exploits/18199

This Perl script exploits multiple unauthenticated DoS vulnerabilities in D-Link DNS-320 devices by sending crafted POST requests to various CGI endpoints, triggering reboot, shutdown, or factory reset. The exploit uses LWP::UserAgent to repeatedly send requests in an infinite loop.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: D-Link DNS-320 (Firmware v2.00b06)
No auth needed
Prerequisites: Network access to the target device · CGI endpoints exposed on the web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026