EIP-2026-101403
PRE-CVEOsprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101403. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit targets an unauthenticated command injection vulnerability in Osprey Pump Controller 1.0.1, allowing remote code execution with www-data permissions via multiple vectors including DataLogView.php and index.php. It establishes a reverse shell using Python's socket and subprocess modules.
Description
Osprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit
Exploits (1)
This exploit targets an unauthenticated command injection vulnerability in Osprey Pump Controller 1.0.1, allowing remote code execution with www-data permissions via multiple vectors including DataLogView.php and index.php. It establishes a reverse shell using Python's socket and subprocess modules.