EIP-2026-120643

PRE-CVE

D-Link DIR-650IN - Authenticated Command Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-120643. PoCs published by Sanjay Singh.

AI-analyzed exploit summary This exploit demonstrates an authenticated command injection vulnerability in the D-Link DIR-650IN router's diagnostic functionality. The `sysHost` parameter in the HTTP POST request is not sanitized, allowing command injection via pipe characters, leading to arbitrary command execution and information disclosure.

Description

D-Link DIR-650IN - Authenticated Command Injection

Exploits (1)

exploitdb WORKING POC
by Sanjay Singh · textwebappsmultiple
https://www.exploit-db.com/exploits/52508

This exploit demonstrates an authenticated command injection vulnerability in the D-Link DIR-650IN router's diagnostic functionality. The `sysHost` parameter in the HTTP POST request is not sanitized, allowing command injection via pipe characters, leading to arbitrary command execution and information disclosure.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: D-Link DIR-650IN Firmware V1.04
Auth required
Prerequisites: Authenticated access to the router's web interface
devstral-2 · analyzed Apr 11, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Apr 11, 2026