PoC Archive PoC Archive

tag

Router

Critical
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
CVE-2022-26258· D-Link DIR-820L wireless router, all hardware revisions unpatched
Critical
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
CVE-2025-54322· XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment) unpatched
Critical
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384· Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint) unpatched
Critical
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854· D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface) patched
High
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459· Zyxel VMG3625-T50B (and similar) router firmware unpatched
High
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
CVE-2026-34474· ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers unpatched
Critical
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472· ZTE ZXHN H188A V6 home router firmware unpatched
High
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473· ZTE H-series routers (17+ models, reported as affecting 140K+ devices) unpatched
Critical
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834· TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6 unpatched
High
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499· Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar) unpatched
High
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992· MR9600 router (Bluetooth-capable administrative interface) unpatched
Critical
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
CVE-2026-36356· MeiG Smart FORGE_SLT711 4G LTE CPE (GoAhead web server) unpatched