EIP-2026-101259

PRE-CVE

Eaton Xpert Meter 13.4.0.10 - SSH Private Key Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101259. PoCs published by BrianWGray.

AI-analyzed exploit summary This exploit leverages a hardcoded SSH private key in Eaton Xpert Meter firmware versions <= 12.x and <= 13.3.x.x to authenticate as 'admin' without a password, enabling unauthorized remote access. The PoC uses the Net::SSH library to establish a session and spawns a command shell.

Description

Eaton Xpert Meter 13.4.0.10 - SSH Private Key Disclosure

Exploits (1)

exploitdb WORKING POC
by BrianWGray · rubyremotehardware
https://www.exploit-db.com/exploits/45283

This exploit leverages a hardcoded SSH private key in Eaton Xpert Meter firmware versions <= 12.x and <= 13.3.x.x to authenticate as 'admin' without a password, enabling unauthorized remote access. The PoC uses the Net::SSH library to establish a session and spawns a command shell.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Eaton Power Xpert Meter (Firmware <= 12.x, <= 13.3.x.x)
No auth needed
Prerequisites: Network access to the target device's SSH port (22) · Target device running vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026