EIP-2026-101653

PRE-CVE

D-Link Routers - Authentication Bypass (1)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101653. PoCs published by Craig Heffner.

AI-analyzed exploit summary The document describes an authentication bypass vulnerability in multiple D-Link router models (DIR-300, DIR-320, DIR-615 revD) due to improper session handling in PHP-based web interfaces. It provides a proof-of-concept URL that bypasses authentication by manipulating query parameters.

Description

D-Link Routers - Authentication Bypass (1)

Exploits (1)

exploitdb WRITEUP
by Craig Heffner · textwebappshardware
https://www.exploit-db.com/exploits/15666

The document describes an authentication bypass vulnerability in multiple D-Link router models (DIR-300, DIR-320, DIR-615 revD) due to improper session handling in PHP-based web interfaces. It provides a proof-of-concept URL that bypasses authentication by manipulating query parameters.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: D-Link DIR-300, DIR-320, DIR-615 revD (all firmware versions)
No auth needed
Prerequisites: Network access to the router's web interface · Knowledge of the router's IP address
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026