EIP-2026-101855
PRE-CVENASdeluxe NDL-2400r 2.01.09 - OS Command Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101855. PoCs published by SySS GmbH.
AI-analyzed exploit summary This is a working proof-of-concept for an OS command injection vulnerability in the NASdeluxe NDL-2400r web interface. The exploit leverages the 'lang' parameter in a login request to execute arbitrary commands as root, resulting in a reverse shell.
Description
NASdeluxe NDL-2400r 2.01.09 - OS Command Injection
Exploits (1)
exploitdb
WORKING POC
by SySS GmbH · textwebappshardware
https://www.exploit-db.com/exploits/40207
This is a working proof-of-concept for an OS command injection vulnerability in the NASdeluxe NDL-2400r web interface. The exploit leverages the 'lang' parameter in a login request to execute arbitrary commands as root, resulting in a reverse shell.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
NASdeluxe NDL-2400r firmware versions 2.01.09 and likely 2.01.10
No auth needed
Prerequisites:
Network access to the target device · Ability to send HTTP POST requests to the target
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026