EIP-2026-101973

PRE-CVE

Seagate Central 2014.0410.0026-F - Remote Facebook Access Token

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101973. PoCs published by Jeremy Brown.

AI-analyzed exploit summary This exploit leverages passwordless root FTP access to retrieve unencrypted Facebook access tokens stored in /etc/archive_accounts.ser on Seagate Central devices, then uses the tokens to query Facebook's Graph API. It demonstrates an authentication bypass and information leakage vulnerability.

Description

Seagate Central 2014.0410.0026-F - Remote Facebook Access Token

Exploits (1)

exploitdb WORKING POC
by Jeremy Brown · pythonwebappshardware
https://www.exploit-db.com/exploits/37185

This exploit leverages passwordless root FTP access to retrieve unencrypted Facebook access tokens stored in /etc/archive_accounts.ser on Seagate Central devices, then uses the tokens to query Facebook's Graph API. It demonstrates an authentication bypass and information leakage vulnerability.

Classification
Working Poc 95%
Attack Type
Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Seagate Central (version 2014.0410.0026-F)
No auth needed
Prerequisites: Network access to the Seagate Central device · FTP service exposed on the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026