EIP-2026-101678
PRE-CVEECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101678. PoCs published by Neurogenesia.
AI-analyzed exploit summary The exploit demonstrates a CSRF vulnerability in ECOA Building Automation System, allowing unauthorized CRUD operations such as user creation or alarm disarm via crafted HTTP requests. The PoC includes a functional HTML form that submits a malicious request to the target system.
Description
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
Exploits (1)
The exploit demonstrates a CSRF vulnerability in ECOA Building Automation System, allowing unauthorized CRUD operations such as user creation or alarm disarm via crafted HTTP requests. The PoC includes a functional HTML form that submits a malicious request to the target system.