Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-26788. PoCs published by EQSTLab, jun2e0.
AI-analyzed exploit summary This script automates the setup of StrongKey FIDO Server (SKFS) v4.15.0, including dependencies, configuration, and deployment of a basic demo application. It exploits CVE-2025-26788 by configuring a vulnerable environment for further exploitation.
Description
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
Exploits (2)
This script automates the setup of StrongKey FIDO Server (SKFS) v4.15.0, including dependencies, configuration, and deployment of a basic demo application. It exploits CVE-2025-26788 by configuring a vulnerable environment for further exploitation.
This repository provides a Docker-based environment setup for exploiting CVE-2025-26788, which targets StrongKey FIDO Server (SKFS) v4.15.0. It includes a Dockerfile, setup script, and instructions to deploy a vulnerable instance for testing.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L