EIP-2026-101240
PRE-CVED-Link DNR-322L <=2.60B15 - Authenticated Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101240. PoCs published by luka.
AI-analyzed exploit summary This exploit leverages an authenticated configuration backup restoration vulnerability in D-Link DNR-322L devices to inject a reverse shell payload into the rc.init.sh script, which executes upon device reboot. The PoC automates login, backup download, payload injection, and restoration.
Description
D-Link DNR-322L <=2.60B15 - Authenticated Remote Code Execution
Exploits (1)
This exploit leverages an authenticated configuration backup restoration vulnerability in D-Link DNR-322L devices to inject a reverse shell payload into the rc.init.sh script, which executes upon device reboot. The PoC automates login, backup download, payload injection, and restoration.