EIP-2026-101293

PRE-CVE

GlobalSunTech Access Point GL2422AP-0T - Information Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101293. PoCs published by Tom Knienieder.

AI-analyzed exploit summary This exploit sends a UDP broadcast packet to port 27155 to trigger an information disclosure vulnerability in GlobalSunTech access points, retrieving sensitive data such as admin credentials, SSID, and WEP keys. The PoC parses the response and displays the leaked information.

Description

GlobalSunTech Access Point GL2422AP-0T - Information Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tom Knienieder · cremotehardware
https://www.exploit-db.com/exploits/21983

This exploit sends a UDP broadcast packet to port 27155 to trigger an information disclosure vulnerability in GlobalSunTech access points, retrieving sensitive data such as admin credentials, SSID, and WEP keys. The PoC parses the response and displays the leaked information.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: GlobalSunTech access points (e.g., WISECOM GL2422AP-0T, Linksys WAP11-V2.2)
No auth needed
Prerequisites: Network access to the target access point · UDP broadcast enabled on the network
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026