EIP-2026-101892
PRE-CVENetlink XPON 1GE WiFi V2801RGW - Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101892. PoCs published by Seecko Das.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Netlink XPON 1GE WiFi V2801RGW firmware V3.3.0-190627. The `target_addr` parameter in the ping form is vulnerable to command injection via the `|` character, allowing remote command execution without authentication.
Description
Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
Exploits (1)
This exploit demonstrates a command injection vulnerability in Netlink XPON 1GE WiFi V2801RGW firmware V3.3.0-190627. The `target_addr` parameter in the ping form is vulnerable to command injection via the `|` character, allowing remote command execution without authentication.