EIP-2026-101828
PRE-CVELenovo R2105 - Cross-Site Request Forgery (Command Execution)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101828. PoCs published by Nathu Nandwani.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Lenovo R2105 routers, allowing an attacker to execute arbitrary commands (e.g., 'reboot') by tricking an authenticated administrator into visiting a malicious webpage. The PoC sets up a local HTTP server that serves a crafted HTML form submitting a command to the router's vulnerable endpoint.
Description
Lenovo R2105 - Cross-Site Request Forgery (Command Execution)
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Lenovo R2105 routers, allowing an attacker to execute arbitrary commands (e.g., 'reboot') by tricking an authenticated administrator into visiting a malicious webpage. The PoC sets up a local HTTP server that serves a crafted HTML form submitting a command to the router's vulnerable endpoint.