EIP-2026-101430

PRE-CVE

Sagemcom F@ST 3890 (50_10_19-T1) Cable Modem - 'Cable Haunt' Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101430. PoCs published by Lyrebirds.

AI-analyzed exploit summary This JavaScript exploit constructs a ROP chain targeting a memory corruption vulnerability in a MIPS-based system, likely a router or embedded device. It sets up a reverse shell by manipulating stack frames and leveraging gadgets to call socket-related functions.

Description

Sagemcom F@ST 3890 (50_10_19-T1) Cable Modem - 'Cable Haunt' Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by Lyrebirds · javascriptremotehardware
https://www.exploit-db.com/exploits/47936

This JavaScript exploit constructs a ROP chain targeting a memory corruption vulnerability in a MIPS-based system, likely a router or embedded device. It sets up a reverse shell by manipulating stack frames and leveraging gadgets to call socket-related functions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Theoretical
Target: Unknown MIPS-based embedded device (likely a router or IoT device)
No auth needed
Prerequisites: Network access to the vulnerable device · MIPS-based architecture with the specific memory layout
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026