EIP-2026-101215
PRE-CVED-Link Devices - 'Authentication.cgi' Remote Buffer Overflow (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101215. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in D-Link routers via the authentication.cgi endpoint by sending a maliciously crafted POST request with an overly long password field. It achieves remote code execution (RCE) on vulnerable D-Link firmware by leveraging ROP gadgets to call system().
Description
D-Link Devices - 'Authentication.cgi' Remote Buffer Overflow (Metasploit)
Exploits (1)
This Metasploit module exploits a buffer overflow in D-Link routers via the authentication.cgi endpoint by sending a maliciously crafted POST request with an overly long password field. It achieves remote code execution (RCE) on vulnerable D-Link firmware by leveraging ROP gadgets to call system().