EIP-2026-100978

PRE-CVE

Addonics NAS Adapter - 'bts.cgi' (Authenticated) Remote Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100978. PoCs published by h00die.

AI-analyzed exploit summary This script exploits a buffer overflow vulnerability in the Addonics NAS Adapter's bts.cgi interface, causing a denial-of-service (DoS) by sending a maliciously crafted GET request with an overly long parameter value. The exploit requires authentication and targets the web GUI, crashing the stack.

Description

Addonics NAS Adapter - 'bts.cgi' (Authenticated) Remote Denial of Service

Exploits (1)

exploitdb WORKING POC VERIFIED
by h00die · bashdoshardware
https://www.exploit-db.com/exploits/8490

This script exploits a buffer overflow vulnerability in the Addonics NAS Adapter's bts.cgi interface, causing a denial-of-service (DoS) by sending a maliciously crafted GET request with an overly long parameter value. The exploit requires authentication and targets the web GUI, crashing the stack.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Addonics NAS Adapter NASU2FW41 Loader 1.17
Auth required
Prerequisites: Valid credentials for the Addonics NAS Adapter web GUI · Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026