EIP-2026-101313

PRE-CVE

Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101313. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Hughes Satellite Router HX200 v8.3.1.14 by injecting a malicious URL into the router's speedtest.html page via cross-frame scripting. The PoC uses JavaScript to dynamically include an external file (XSS.svg) from a remote server, potentially leading to sensitive information theft.

Description

Hughes Satellite Router HX200 v8.3.1.14 - Remote File Inclusion

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/51190

The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Hughes Satellite Router HX200 v8.3.1.14 by injecting a malicious URL into the router's speedtest.html page via cross-frame scripting. The PoC uses JavaScript to dynamically include an external file (XSS.svg) from a remote server, potentially leading to sensitive information theft.

Classification
Working Poc 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Hughes Satellite Router HX200 v8.3.1.14
No auth needed
Prerequisites: Access to the router's web interface · Network connectivity to the target router
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026