EIP-2026-100853
PRE-CVEMESSOA IP Cameras (Multiple Models) - Password Change
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100853. PoCs published by Todor Donev.
AI-analyzed exploit summary This script exploits an authentication bypass vulnerability in multiple MESSOA IP-Cameras to change the admin username and password. It sends a crafted HTTP request to the vulnerable endpoint without requiring prior authentication.
Description
MESSOA IP Cameras (Multiple Models) - Password Change
Exploits (1)
exploitdb
WORKING POC
by Todor Donev · bashwebappscgi
https://www.exploit-db.com/exploits/40277
This script exploits an authentication bypass vulnerability in multiple MESSOA IP-Cameras to change the admin username and password. It sends a crafted HTTP request to the vulnerable endpoint without requiring prior authentication.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
MESSOA IP-Cameras (NIC 835, NIC 835-HN5, NIC 836, NDZ 860)
No auth needed
Prerequisites:
Network access to the target camera · libwww-perl installed for the GET command
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026