EIP-2026-101734
PRE-CVEFlexAir Access Control 2.4.9api3 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101734. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in FlexAir Access Control (Prima Systems) firmware version <= 2.3.38. It leverages the 'GoogleAccessToken' parameter in an XML payload to execute arbitrary commands with root privileges via a POST request to '/bin/sysfcgi.fx'.
Description
FlexAir Access Control 2.4.9api3 - Remote Code Execution
Exploits (1)
This exploit demonstrates a command injection vulnerability in FlexAir Access Control (Prima Systems) firmware version <= 2.3.38. It leverages the 'GoogleAccessToken' parameter in an XML payload to execute arbitrary commands with root privileges via a POST request to '/bin/sysfcgi.fx'.