EIP-2026-100725
PRE-CVEneteyes nexusway border gateway - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100725. PoCs published by pokley.
AI-analyzed exploit summary The exploit demonstrates multiple command injection vulnerabilities in NexusWay devices via crafted HTTP requests to CGI scripts (e.g., `index.cgi`, `ping.cgi`, `nslookup.cgi`). The PoC uses shell metacharacters (`;`, `&&`) to chain arbitrary commands, achieving remote code execution (RCE) without authentication.
Description
neteyes nexusway border gateway - Multiple Vulnerabilities
Exploits (1)
The exploit demonstrates multiple command injection vulnerabilities in NexusWay devices via crafted HTTP requests to CGI scripts (e.g., `index.cgi`, `ping.cgi`, `nslookup.cgi`). The PoC uses shell metacharacters (`;`, `&&`) to chain arbitrary commands, achieving remote code execution (RCE) without authentication.