EIP-2026-101636
PRE-CVED-Link DIR-8xx Routers - Root Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101636. PoCs published by embedi.
AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in the HNAP protocol implementation of D-Link routers, allowing remote command execution as root. It crafts a malicious SOAP request with a payload that overflows the stack and redirects execution to the `system` function.
Description
D-Link DIR-8xx Routers - Root Remote Code Execution
Exploits (1)
exploitdb
WORKING POC
by embedi · pythonwebappshardware
https://www.exploit-db.com/exploits/42730
This exploit targets a stack overflow vulnerability in the HNAP protocol implementation of D-Link routers, allowing remote command execution as root. It crafts a malicious SOAP request with a payload that overflows the stack and redirects execution to the `system` function.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
D-Link DIR-890L (firmware versions including 1.10.B07 and 1.11B02.BETA01)
No auth needed
Prerequisites:
Network access to the target router · HNAP service exposed on port 80
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026