EIP-2026-101825
PRE-CVEKZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101825. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates an unauthenticated configuration disclosure vulnerability in KZTech/JatonTec/Neotel JT3500V 4G LTE CPE devices. By sending a direct HTTP GET request to the export_settings.cgi file, an attacker can download sensitive configuration data, potentially leading to authentication bypass and full system access.
Description
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
Exploits (1)
The exploit demonstrates an unauthenticated configuration disclosure vulnerability in KZTech/JatonTec/Neotel JT3500V 4G LTE CPE devices. By sending a direct HTTP GET request to the export_settings.cgi file, an attacker can download sensitive configuration data, potentially leading to authentication bypass and full system access.