EIP-2026-100775
PRE-CVECHIYU TCP/IP Converter devices - CRLF injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100775. PoCs published by sirpedrotavares.
AI-analyzed exploit summary This exploit demonstrates a CRLF injection vulnerability in CHIYU TCP/IP Converter devices (BF-430, BF-431, BF-450M) by injecting a malicious script via the 'redirect' parameter in a GET request. The payload bypasses input validation to execute arbitrary JavaScript in the HTTP response.
Description
CHIYU TCP/IP Converter devices - CRLF injection
Exploits (1)
This exploit demonstrates a CRLF injection vulnerability in CHIYU TCP/IP Converter devices (BF-430, BF-431, BF-450M) by injecting a malicious script via the 'redirect' parameter in a GET request. The payload bypasses input validation to execute arbitrary JavaScript in the HTTP response.