EIP-2026-101576

PRE-CVE

Broadlight Residential Gateway DI3124 - Remote DNS Change

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101576. PoCs published by Todor Donev.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote DNS change vulnerability in Broadlight Residential Gateway DI3124. It allows an attacker to modify DNS settings and retrieve default credentials via HTTP GET requests to specific CGI endpoints.

Description

Broadlight Residential Gateway DI3124 - Remote DNS Change

Exploits (1)

exploitdb WORKING POC
by Todor Donev · textwebappshardware
https://www.exploit-db.com/exploits/37214

This exploit demonstrates an unauthenticated remote DNS change vulnerability in Broadlight Residential Gateway DI3124. It allows an attacker to modify DNS settings and retrieve default credentials via HTTP GET requests to specific CGI endpoints.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Broadlight Residential Gateway DI3124
No auth needed
Prerequisites: Network access to the target device · Target device must be running thttpd/2.25b 29dec2003
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026