A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_set_wto of the file /cgi-bin/system_mgr.cgi. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.
[POC] CVE-2026-41940 — cpanel2shell-scanner
High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)
[POC] CVE-2026-41940 — cPanelWHM-AuthBypass
CVE-2026-41940
[POC] CVE-2026-41940 — cPanel-CVE-2026-41940-Scanner
Advanced cPanel & WHM Security Scanner for CVE-2026-41940. with mass Shodan discovery
[POC] CVE-2026-41940 — CVE-2026-41940-cpanel-0day
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
[POC] GHSA-652q-gvq3-74qv — CVE-2026-41940
CVE-2026-41940
[POC] CVE-2026-41940 — portscan-CVE-2026-41940
IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness
[POC] CVE-2026-41940 — cve-2026-41940-exploit
improved poc of cve-2026-41940
[POC] CVE-2026-41940 — CVE-2026-41940-Linux
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
[POC] CVE-2026-41940 — 2026-41940-poc
CVE-2026-41940: detect and exploit cpanel vuln
[POC] CVE-2026-41940 — CVE-2026-41940
PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testing only.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free