EIP-2026-102053
PRE-CVETP-Link - Admin Panel Multiple Cross-Site Request Forgery Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102053. PoCs published by CYBSEC Labs.
AI-analyzed exploit summary This is a vulnerability advisory detailing multiple CSRF vulnerabilities in TP-LINK Admin Panel firmware v3.13.6 Build 110923 Rel.53137n. It includes proof-of-concept URLs for exploiting CSRF to create new users and disable the firewall.
Description
TP-Link - Admin Panel Multiple Cross-Site Request Forgery Vulnerabilities
Exploits (1)
exploitdb
WRITEUP
by CYBSEC Labs · textwebappshardware
https://www.exploit-db.com/exploits/24483
This is a vulnerability advisory detailing multiple CSRF vulnerabilities in TP-LINK Admin Panel firmware v3.13.6 Build 110923 Rel.53137n. It includes proof-of-concept URLs for exploiting CSRF to create new users and disable the firewall.
Classification
Writeup 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:
TP-LINK Admin Panel (Firmware v3.13.6 Build 110923 Rel.53137n)
Auth required
Prerequisites:
Victim must be authenticated to the TP-LINK Admin Panel · Victim must visit a malicious website crafted by the attacker
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026