EIP-2026-100786
PRE-CVEDevice42 WAN Emulator 2.3 - Traceroute Command Injection (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100786. PoCs published by Brandon Perry.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in WAN Emulator v2.3 by authenticating as a default admin user and injecting a malicious payload into the 'traceip' parameter of the ping functionality. The payload is base64-encoded and executed via a command substitution attack.
Description
Device42 WAN Emulator 2.3 - Traceroute Command Injection (Metasploit)
Exploits (1)
This Metasploit module exploits a command injection vulnerability in WAN Emulator v2.3 by authenticating as a default admin user and injecting a malicious payload into the 'traceip' parameter of the ping functionality. The payload is base64-encoded and executed via a command substitution attack.