EIP-2026-101154
PRE-CVEAllied Telesis AT-MCF2000M 3.0.2 - Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101154. PoCs published by dun.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Allied Telesis AT-MCF2000M 3.0.2 via the 'File Show Filesystem' command, allowing an authenticated attacker to execute arbitrary commands and gain a root shell by injecting shell metacharacters (e.g., |, &, ;). The PoC shows how to spawn a telnetd service on port 30 with a root shell.
Description
Allied Telesis AT-MCF2000M 3.0.2 - Remote Command Execution
Exploits (1)
This exploit demonstrates a command injection vulnerability in Allied Telesis AT-MCF2000M 3.0.2 via the 'File Show Filesystem' command, allowing an authenticated attacker to execute arbitrary commands and gain a root shell by injecting shell metacharacters (e.g., |, &, ;). The PoC shows how to spawn a telnetd service on port 30 with a root shell.