EIP-2026-101241

PRE-CVE

D-Link DNS-320 ShareCenter < 1.06 - Backdoor Access

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101241. PoCs published by GulfTech Security.

AI-analyzed exploit summary This document details a hardcoded backdoor in D-Link DNS-320L ShareCenter firmware < 1.06, allowing authentication bypass with credentials 'mydlinkBRionyg' and 'abc12345cba'. It also describes a command injection vulnerability to achieve remote root shell access via log poisoning and PHP shell creation.

Description

D-Link DNS-320 ShareCenter < 1.06 - Backdoor Access

Exploits (1)

exploitdb WRITEUP
by GulfTech Security · textremotehardware
https://www.exploit-db.com/exploits/43434

This document details a hardcoded backdoor in D-Link DNS-320L ShareCenter firmware < 1.06, allowing authentication bypass with credentials 'mydlinkBRionyg' and 'abc12345cba'. It also describes a command injection vulnerability to achieve remote root shell access via log poisoning and PHP shell creation.

Classification
Writeup 100%
Attack Type
Auth Bypass | Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DNS-320L ShareCenter < 1.06
No auth needed
Prerequisites: Network access to the device · CGI endpoint accessibility
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026