D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.
- http://www.exploit-db.com/exploits/22930/
- https://packetstormsecurity.com/files/118355/D-Link-DSR-250N-Backdoor.html
No PoCs found on GitHub currently.