EIP-2026-101520

PRE-CVE

Alpha Networks ADSL2/2+ Wireless Router ASL-26555 - Password Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101520. PoCs published by Alberto Ortega.

AI-analyzed exploit summary This exploit discloses the administrator credentials of Alpha Networks ADSL2/2+ Wireless Router ASL-26555 by accessing an unauthenticated API endpoint. The API endpoint `/APIS/returnJSON.htm` returns the username and password in JSON format, allowing unauthorized access to the device's web panel.

Description

Alpha Networks ADSL2/2+ Wireless Router ASL-26555 - Password Disclosure

Exploits (1)

exploitdb WORKING POC
by Alberto Ortega · textwebappshardware
https://www.exploit-db.com/exploits/20667

This exploit discloses the administrator credentials of Alpha Networks ADSL2/2+ Wireless Router ASL-26555 by accessing an unauthenticated API endpoint. The API endpoint `/APIS/returnJSON.htm` returns the username and password in JSON format, allowing unauthorized access to the device's web panel.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Alpha Networks ADSL2/2+ Wireless Router ASL-26555 (firmware v2.0.0.30B_ES)
No auth needed
Prerequisites: Network access to the router's web interface on port 8000
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026