EIP-2026-101750
PRE-CVEGemtek CPE7000 - WLTCS-106 Administrator SID Retriever (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101750. PoCs published by Federico Scalco.
AI-analyzed exploit summary This Metasploit auxiliary module exploits an information leak vulnerability in Gemtek CPE7000 (WLTCS-106) to retrieve a valid administrative SID without authentication. The SID can then be used to gain administrative access by injecting it into the session cookie.
Description
Gemtek CPE7000 - WLTCS-106 Administrator SID Retriever (Metasploit)
Exploits (1)
exploitdb
WORKING POC
by Federico Scalco · rubywebappshardware
https://www.exploit-db.com/exploits/39725
This Metasploit auxiliary module exploits an information leak vulnerability in Gemtek CPE7000 (WLTCS-106) to retrieve a valid administrative SID without authentication. The SID can then be used to gain administrative access by injecting it into the session cookie.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Gemtek CPE7000 WLTCS-106 (Firmware 01.01.02.082)
No auth needed
Prerequisites:
Network access to the target device on port 443
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026