EIP-2026-101936

PRE-CVE

QNAP Turbo NAS TS-1279U-RP - Multiple Path Injections

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101936. PoCs published by Andrea Fabrizi.

AI-analyzed exploit summary This is a technical writeup detailing a path injection vulnerability in QNAP Turbo NAS devices. It describes how authenticated users can exploit the '/cgi-bin/filemanager/utilRequest.cgi' endpoint to access, delete, or modify system files, including sensitive files like '/etc/shadow'.

Description

QNAP Turbo NAS TS-1279U-RP - Multiple Path Injections

Exploits (1)

exploitdb WRITEUP
by Andrea Fabrizi · textwebappshardware
https://www.exploit-db.com/exploits/21081

This is a technical writeup detailing a path injection vulnerability in QNAP Turbo NAS devices. It describes how authenticated users can exploit the '/cgi-bin/filemanager/utilRequest.cgi' endpoint to access, delete, or modify system files, including sensitive files like '/etc/shadow'.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: QNAP Turbo NAS <= 3.7.3 build 20120801
Auth required
Prerequisites: Authenticated access to the QNAP Turbo NAS device
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026