EIP-2026-101297

PRE-CVE

Herospeed - 'TelnetSwitch' Remote Stack Overflow / Overwrite Password / Enable TelnetD

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101297. PoCs published by bashis.

AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in the Herospeed TelnetSwitch daemon (TCP/787) to overwrite the dynamically generated password and enable telnetd. It uses a base64-encoded payload with a hardcoded login and iteratively overwrites the password in memory.

Description

Herospeed - 'TelnetSwitch' Remote Stack Overflow / Overwrite Password / Enable TelnetD

Exploits (1)

exploitdb WORKING POC
by bashis · pythonremotehardware
https://www.exploit-db.com/exploits/43997

This exploit targets a stack overflow vulnerability in the Herospeed TelnetSwitch daemon (TCP/787) to overwrite the dynamically generated password and enable telnetd. It uses a base64-encoded payload with a hardcoded login and iteratively overwrites the password in memory.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Herospeed TelnetSwitch daemon (affecting Fullhan IPC, HiSilicon, and Ambarella devices)
No auth needed
Prerequisites: Network access to TCP/787 on the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026