EIP-2026-101773

PRE-CVE

Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore < 14.8.7825.01 - IDOR

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101773. PoCs published by Arslan Masood.

AI-analyzed exploit summary This exploit leverages an Insecure Direct Object Reference (IDOR) vulnerability in Hitachi NAS (HNAS) System Management Unit (SMU) to download backup archives without proper authorization. It sends a crafted GET request with valid session cookies to retrieve sensitive backup files.

Description

Hitachi NAS (HNAS) System Management Unit (SMU) Backup & Restore < 14.8.7825.01 - IDOR

Exploits (1)

exploitdb WORKING POC
by Arslan Masood · pythonwebappshardware
https://www.exploit-db.com/exploits/51872

This exploit leverages an Insecure Direct Object Reference (IDOR) vulnerability in Hitachi NAS (HNAS) System Management Unit (SMU) to download backup archives without proper authorization. It sends a crafted GET request with valid session cookies to retrieve sensitive backup files.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Hitachi NAS (HNAS) System Management Unit (SMU) < 14.8.7825.01
Auth required
Prerequisites: Valid JSESSIONID and JSESSIONIDSSO cookies · Network access to the target SMU
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026