EIP-2026-101399
PRE-CVEOsprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101399. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Osprey Pump Controller v1.0.1 by modifying user credentials via unauthenticated HTTP requests to the 'setSystemText.php' endpoint. It creates a new user account with specified credentials by manipulating 'USERNAME3' and 'USERPW3' system strings.
Description
Osprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Osprey Pump Controller v1.0.1 by modifying user credentials via unauthenticated HTTP requests to the 'setSystemText.php' endpoint. It creates a new user account with specified credentials by manipulating 'USERNAME3' and 'USERPW3' system strings.