<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Router — PoC Archive</title><link>https://poc.intelseclab.com/tags/router/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/router/index.xml" rel="self" type="application/rss+xml"/><item><title>D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-26258. Status: Weaponized (public PoC available; listed in CISA KEV). Affects: D-Link DIR-820L wireless router, all hardware revisions. Tags: d-link, dir-820l, router, command-injection, cwe-78, unauthenticated, remote, iot, eol-device, kev.</description><category>network</category><category>Critical</category><category>d-link</category><category>dir-820l</category><category>router</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>remote</category><category>iot</category><category>eol-device</category><category>kev</category></item><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-29384. Status: PoC. Affects: Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint). Tags: tenda, ac9, router, stack-buffer-overflow, cwe-121, dos, rce, mips, embedded, iot, python, ruby, metasploit.</description><category>network</category><category>Critical</category><category>tenda</category><category>ac9</category><category>router</category><category>stack-buffer-overflow</category><category>cwe-121</category><category>dos</category><category>rce</category><category>mips</category><category>embedded</category><category>iot</category><category>python</category><category>ruby</category><category>metasploit</category></item><item><title>D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-60854. Status: Weaponized. Affects: D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface). Tags: d-link, ax1500, router, command-injection, os-command-injection, hnap, soap, telnetd, cwe-78, iot.</description><category>network</category><category>Critical</category><category>d-link</category><category>ax1500</category><category>router</category><category>command-injection</category><category>os-command-injection</category><category>hnap</category><category>soap</category><category>telnetd</category><category>cwe-78</category><category>iot</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</guid><description>High severity — network · CVE-2026-34474. Status: PoC. Affects: ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers. Tags: information-disclosure, router, firmware, unauthenticated, credential-leak, iot, zte, wifi.</description><category>network</category><category>High</category><category>information-disclosure</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</guid><description>Critical severity — network · CVE-2026-34472. Status: PoC. Affects: ZTE ZXHN H188A V6 home router firmware. Tags: router, firmware, unauthenticated, auth-bypass, credential-leak, iot, zte, wifi.</description><category>network</category><category>Critical</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>auth-bypass</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</guid><description>High severity — network · CVE-2026-34473. Status: PoC. Affects: ZTE H-series routers (17+ models, reported as affecting 140K+ devices). Tags: router, firmware, unauthenticated, denial-of-service, iot, zte, cgilua, web-interface.</description><category>network</category><category>High</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>denial-of-service</category><category>iot</category><category>zte</category><category>cgilua</category><category>web-interface</category></item><item><title>TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</guid><description>Critical severity — network · CVE-2026-11834. Status: Weaponized. Affects: TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6. Tags: tp-link, router, dhcp, command-injection, cwe-78, race-condition, rce, iot.</description><category>network</category><category>Critical</category><category>tp-link</category><category>router</category><category>dhcp</category><category>command-injection</category><category>cwe-78</category><category>race-condition</category><category>rce</category><category>iot</category></item><item><title>TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-8697. Status: PoC. Affects: TP-Link Archer C64 router firmware ("TPOS"). Tags: tplink, archer-c64, router, ssh, rate-limit-bypass, authentication-oracle, brute-force, iot.</description><category>network</category><category>Critical</category><category>tplink</category><category>archer-c64</category><category>router</category><category>ssh</category><category>rate-limit-bypass</category><category>authentication-oracle</category><category>brute-force</category><category>iot</category></item><item><title>Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</guid><description>High severity — network · CVE-2026-11499. Status: PoC. Affects: Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar). Tags: tenda, router, buffer-overflow, cwe-121, dos, embedded, iot, rce.</description><category>network</category><category>High</category><category>tenda</category><category>router</category><category>buffer-overflow</category><category>cwe-121</category><category>dos</category><category>embedded</category><category>iot</category><category>rce</category></item><item><title>MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6992-mr9600-router-bluetooth-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6992-mr9600-router-bluetooth-rce/</guid><description>High severity — network · CVE-2026-6992. Status: PoC. Affects: MR9600 router (Bluetooth-capable administrative interface). Tags: router, bluetooth, jnap, command-injection, iot, rce.</description><category>network</category><category>High</category><category>router</category><category>bluetooth</category><category>jnap</category><category>command-injection</category><category>iot</category><category>rce</category></item><item><title>MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36356-meig-smart-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36356-meig-smart-router-command-injection/</guid><description>Critical severity — network · CVE-2026-36356. Status: Weaponized. Affects: MeiG Smart FORGE_SLT711 4G LTE CPE (GoAhead web server). Tags: meig-smart, 4g-lte-cpe, router, command-injection, goahead, unauthenticated, root, cwe-78, cwe-306.</description><category>network</category><category>Critical</category><category>meig-smart</category><category>4g-lte-cpe</category><category>router</category><category>command-injection</category><category>goahead</category><category>unauthenticated</category><category>root</category><category>cwe-78</category><category>cwe-306</category></item></channel></rss>