EIP-2026-103349
PRE-CVEEir D1000 Wireless Router - WAN Side Remote Command Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103349. PoCs published by Kenzo.
AI-analyzed exploit summary This Metasploit module exploits a remote command injection vulnerability in the Eir D1000 Wireless Router by sending maliciously crafted TR-064 SOAP requests to manipulate firewall rules and retrieve the Wi-Fi password. It leverages the CWMP port (7547) to execute arbitrary commands via the `SetNTPServers` function.
Description
Eir D1000 Wireless Router - WAN Side Remote Command Injection (Metasploit)
Exploits (1)
This Metasploit module exploits a remote command injection vulnerability in the Eir D1000 Wireless Router by sending maliciously crafted TR-064 SOAP requests to manipulate firewall rules and retrieve the Wi-Fi password. It leverages the CWMP port (7547) to execute arbitrary commands via the `SetNTPServers` function.