EIP-2026-120643
PRE-CVED-Link DIR-650IN - Authenticated Command Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-120643. PoCs published by Sanjay Singh.
AI-analyzed exploit summary This exploit demonstrates an authenticated command injection vulnerability in the D-Link DIR-650IN router's diagnostic functionality. The `sysHost` parameter in the HTTP POST request is not sanitized, allowing command injection via pipe characters, leading to arbitrary command execution and information disclosure.
Description
D-Link DIR-650IN - Authenticated Command Injection
Exploits (1)
This exploit demonstrates an authenticated command injection vulnerability in the D-Link DIR-650IN router's diagnostic functionality. The `sysHost` parameter in the HTTP POST request is not sanitized, allowing command injection via pipe characters, leading to arbitrary command execution and information disclosure.