EIP-2026-101254

PRE-CVE

Dixell XWEB 500 - Arbitrary File Write

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101254. PoCs published by Roberto Palamaro.

AI-analyzed exploit summary This exploit demonstrates arbitrary file write vulnerabilities in Dixell XWEB-500 via three endpoints: logo_extra_upload.cgi, lo_utils.cgi, and cal_save.cgi. It uses curl commands to send POST requests with file content, enabling unauthorized file creation or modification.

Description

Dixell XWEB 500 - Arbitrary File Write

Exploits (1)

exploitdb WORKING POC
by Roberto Palamaro · textremotehardware
https://www.exploit-db.com/exploits/50639

This exploit demonstrates arbitrary file write vulnerabilities in Dixell XWEB-500 via three endpoints: logo_extra_upload.cgi, lo_utils.cgi, and cal_save.cgi. It uses curl commands to send POST requests with file content, enabling unauthorized file creation or modification.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Dixell XWEB-500
No auth needed
Prerequisites: Network access to the target device · Curl or similar HTTP client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026