EIP-2026-101636

PRE-CVE

D-Link DIR-8xx Routers - Root Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101636. PoCs published by embedi.

AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in the HNAP protocol implementation of D-Link routers, allowing remote command execution as root. It crafts a malicious SOAP request with a payload that overflows the stack and redirects execution to the `system` function.

Description

D-Link DIR-8xx Routers - Root Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by embedi · pythonwebappshardware
https://www.exploit-db.com/exploits/42730

This exploit targets a stack overflow vulnerability in the HNAP protocol implementation of D-Link routers, allowing remote command execution as root. It crafts a malicious SOAP request with a payload that overflows the stack and redirects execution to the `system` function.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: D-Link DIR-890L (firmware versions including 1.10.B07 and 1.11B02.BETA01)
No auth needed
Prerequisites: Network access to the target router · HNAP service exposed on port 80
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026