EIP-2026-101614

PRE-CVE

D-Link - OS-Command Injection via UPnP Interface

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101614. PoCs published by m-1-k-3.

AI-analyzed exploit summary This advisory describes an unauthenticated OS command injection vulnerability in multiple D-Link devices via the UPnP SOAP interface. The vulnerability allows arbitrary command execution through manipulated XML parameters such as NewInternalClient, NewExternalPort, and NewInternalPort.

Description

D-Link - OS-Command Injection via UPnP Interface

Exploits (1)

exploitdb WRITEUP
by m-1-k-3 · textwebappshardware
https://www.exploit-db.com/exploits/26664

This advisory describes an unauthenticated OS command injection vulnerability in multiple D-Link devices via the UPnP SOAP interface. The vulnerability allows arbitrary command execution through manipulated XML parameters such as NewInternalClient, NewExternalPort, and NewInternalPort.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: D-Link DIR-300 rev B (2.14b01), DIR-600 (2.16b01), DIR-645 (1.04b01), DIR-845 (1.01b02), DIR-865 (1.05b03)
No auth needed
Prerequisites: Network access to the vulnerable device · UPnP SOAP interface enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026