Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-101612. PoCs published by Saurabh Harit.
AI-analyzed exploit summary This advisory details an OS command injection vulnerability in Cyberoam UTM appliances, where the 'host' parameter in diagnostic tools lacks server-side validation, allowing authenticated users to execute arbitrary commands as root. It also describes insecure password handling where domain credentials are exposed to authenticated clients.
Description
Cyberoam UTM - Multiple Vulnerabilities
Exploits (1)
This advisory details an OS command injection vulnerability in Cyberoam UTM appliances, where the 'host' parameter in diagnostic tools lacks server-side validation, allowing authenticated users to execute arbitrary commands as root. It also describes insecure password handling where domain credentials are exposed to authenticated clients.