EIP-2026-101855

PRE-CVE

NASdeluxe NDL-2400r 2.01.09 - OS Command Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101855. PoCs published by SySS GmbH.

AI-analyzed exploit summary This is a working proof-of-concept for an OS command injection vulnerability in the NASdeluxe NDL-2400r web interface. The exploit leverages the 'lang' parameter in a login request to execute arbitrary commands as root, resulting in a reverse shell.

Description

NASdeluxe NDL-2400r 2.01.09 - OS Command Injection

Exploits (1)

exploitdb WORKING POC
by SySS GmbH · textwebappshardware
https://www.exploit-db.com/exploits/40207

This is a working proof-of-concept for an OS command injection vulnerability in the NASdeluxe NDL-2400r web interface. The exploit leverages the 'lang' parameter in a login request to execute arbitrary commands as root, resulting in a reverse shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: NASdeluxe NDL-2400r firmware versions 2.01.09 and likely 2.01.10
No auth needed
Prerequisites: Network access to the target device · Ability to send HTTP POST requests to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026