EIP-2026-101514

PRE-CVE

Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101514. PoCs published by Ike-Clinton.

AI-analyzed exploit summary This exploit leverages a local file inclusion (LFI) vulnerability in AeroHive AP340 HiveOS < 6.1r5 by injecting PHP code into the login page, which poisons the log file at /var/log/messages. It then uses the LFI to execute arbitrary commands, specifically changing the root password for SSH access.

Description

Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by Ike-Clinton · pythonwebappshardware
https://www.exploit-db.com/exploits/42178

This exploit leverages a local file inclusion (LFI) vulnerability in AeroHive AP340 HiveOS < 6.1r5 by injecting PHP code into the login page, which poisons the log file at /var/log/messages. It then uses the LFI to execute arbitrary commands, specifically changing the root password for SSH access.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AeroHive AP340 HiveOS < 6.1r5
No auth needed
Prerequisites: Network access to the target device · Login page accessible at /login.php5
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026