EIP-2026-101312

PRE-CVE

Huawei SmartAX MT880 - Multiple Cross-Site Request Forgery Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101312. PoCs published by Jerome Athias.

AI-analyzed exploit summary The exploit demonstrates multiple CSRF vulnerabilities in Huawei MT880 firmware, allowing unauthorized actions such as adding admin users, disabling firewall features, and modifying MAC/IP whitelists via crafted HTTP requests. Default credentials (admin/admin) are exposed, enabling authentication bypass.

Description

Huawei SmartAX MT880 - Multiple Cross-Site Request Forgery Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jerome Athias · textremotehardware
https://www.exploit-db.com/exploits/9503

The exploit demonstrates multiple CSRF vulnerabilities in Huawei MT880 firmware, allowing unauthorized actions such as adding admin users, disabling firewall features, and modifying MAC/IP whitelists via crafted HTTP requests. Default credentials (admin/admin) are exposed, enabling authentication bypass.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Huawei MT880 firmware
Auth required
Prerequisites: Network access to the device · Default credentials or valid admin session
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026