EIP-2026-101614
PRE-CVED-Link - OS-Command Injection via UPnP Interface
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101614. PoCs published by m-1-k-3.
AI-analyzed exploit summary This advisory describes an unauthenticated OS command injection vulnerability in multiple D-Link devices via the UPnP SOAP interface. The vulnerability allows arbitrary command execution through manipulated XML parameters such as NewInternalClient, NewExternalPort, and NewInternalPort.
Description
D-Link - OS-Command Injection via UPnP Interface
Exploits (1)
This advisory describes an unauthenticated OS command injection vulnerability in multiple D-Link devices via the UPnP SOAP interface. The vulnerability allows arbitrary command execution through manipulated XML parameters such as NewInternalClient, NewExternalPort, and NewInternalPort.