CVE-2010-2075

UnrealIRCd 3.2.8.1 - Remote Code Execution via Trojaned DEBUG3_DOLOG_SYSTEM Macro

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 10 public exploits for CVE-2010-2075. PoCs published by Metasploit, anonymous, MFernstrom, including Metasploit module exploits/unix/irc/unreal_ircd_3281_backdoor.

AI-analyzed exploit summary This Metasploit module exploits a backdoor in UnrealIRCD 3.2.8.1, allowing remote command execution via a malicious command sent to the IRC server. The backdoor was present in the Unreal3.2.8.1.tar.gz archive between November 2009 and June 12th 2010.

Description

UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.

Exploits (10)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16922

This Metasploit module exploits a backdoor in UnrealIRCD 3.2.8.1, allowing remote command execution via a malicious command sent to the IRC server. The backdoor was present in the Unreal3.2.8.1.tar.gz archive between November 2009 and June 12th 2010.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCD 3.2.8.1
No auth needed
Prerequisites: Network access to the target IRC server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by anonymous · perlremotelinux
https://www.exploit-db.com/exploits/13853

This exploit targets a remote command execution vulnerability in UnrealIRCd 3.2.8.1 by sending malicious payloads via a TCP socket. It allows an attacker to download and execute arbitrary scripts, terminate processes, or delete files on the target system.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target UnrealIRCd server · UnrealIRCd 3.2.8.1 running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by MFernstrom · poc
https://github.com/MFernstrom/OffensivePascal-CVE-2010-2075

This repository contains a FreePascal implementation of an exploit for CVE-2010-2075, which allows remote command execution in UnrealIRCd 3.2.8.1 by sending a crafted payload. The exploit establishes a reverse shell to a specified listener.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target UnrealIRCd service · Listener set up for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by FredBrave · poc
https://github.com/FredBrave/CVE-2010-2075-UnrealIRCd-3.2.8.1

This repository contains a functional exploit for CVE-2010-2075, a backdoor in UnrealIRCd 3.2.8.1 that allows remote command execution. The exploit sends a crafted payload with the prefix 'AB;' to trigger the backdoor and execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target IRC server · UnrealIRCd 3.2.8.1 running on the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by mishaqdev · poc
https://github.com/mishaqdev/cve-2010-2075-analysis

This repository provides a detailed analysis of CVE-2010-2075, a backdoor vulnerability in UnrealIRCd 3.2.8.1, including lab setup, exploitation steps, and remediation advice. It references an external PDF for full technical details.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: UnrealIRCd 3.2.8.1 running on port 6667 · Network access to the target
devstral-2 · analyzed Jun 06, 2026 Full analysis →
nomisec WORKING POC
by Tc-XoNoR · poc
https://github.com/Tc-XoNoR/CVE-2010-2075

This repository contains a functional Bash exploit for CVE-2010-2075, targeting the backdoor in UnrealIRCd 3.2.8.1. The exploit sends a crafted payload prefixed with 'AB;' to execute a reverse shell via /dev/tcp.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: network access to the target IRC port · listener set up on attacker machine
devstral-2 · analyzed Apr 17, 2026 Full analysis →
nomisec WORKING POC
by earthbendergara · poc
https://github.com/earthbendergara/unrealircd3.2.8.1-local-exploit

This repository contains functional exploit code for CVE-2010-2075, targeting UnrealIRCd 3.2.8.1. The exploit leverages a backdoor command injection vulnerability to execute arbitrary commands and establish a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target IRC server · Target running UnrealIRCd 3.2.8.1
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by JoseLRC97 · poc
https://github.com/JoseLRC97/UnrealIRCd-3.2.8.1-Backdoor-Command-Execution

This repository contains a functional Python exploit for CVE-2010-2075, which targets a backdoor in UnrealIRCd 3.2.8.1. The exploit sends a crafted payload to establish a reverse shell connection to an attacker-controlled host.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target UnrealIRCd service · Attacker-controlled host to receive the reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by chancej715 · poc
https://github.com/chancej715/UnrealIRCd-3.2.8.1-Backdoor-Command-Execution

This repository contains a functional Python exploit for CVE-2010-2075, which leverages a backdoor in UnrealIRCd 3.2.8.1 to execute arbitrary commands via a crafted payload sent to the target IRC server. The exploit establishes a reverse shell to a listener specified by the attacker.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCd 3.2.8.1
No auth needed
Prerequisites: Network access to the target IRC server · Listener set up on attacker's machine
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/irc/unreal_ircd_3281_backdoor.rb

This Metasploit module exploits a backdoor in UnrealIRCD 3.2.8.1 by sending a malicious command ('AB;') followed by a payload to execute arbitrary commands on the target system. The exploit connects to the IRC server, sends the backdoor command, and handles the resulting session.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: UnrealIRCD 3.2.8.1
No auth needed
Prerequisites: Network access to the target IRC server on port 6667
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/65445
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/06/14/11
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1437
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201006-21.xml
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/13853
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40169
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Jun/277
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40820
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Jun/284

Scores

EPSS 0.8768
EPSS Percentile 99.5%

Details

CWE
CWE-20
Status published
Products (1)
unrealircd/unrealircd 3.2.8.1
Published Jun 15, 2010
Tracked Since Feb 18, 2026