EIP-2026-101998

PRE-CVE

Sielco PolyEco Digital FM Transmitter 2.0.6 - Authorization Bypass Factory Reset

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101998. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit describes an authorization bypass vulnerability in Sielco PolyEco Digital FM Transmitter due to improper access control. Attackers can manipulate client-side JavaScript or server responses to elevate privileges and access protected pages like the factory reset page.

Description

Sielco PolyEco Digital FM Transmitter 2.0.6 - Authorization Bypass Factory Reset

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/51368

The exploit describes an authorization bypass vulnerability in Sielco PolyEco Digital FM Transmitter due to improper access control. Attackers can manipulate client-side JavaScript or server responses to elevate privileges and access protected pages like the factory reset page.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sielco PolyEco Digital FM Transmitter (versions 2.0.6, 1.9.4, 1.9.3, 1.7.0, 2.0.2, 2.0.0)
No auth needed
Prerequisites: Network access to the target device · Ability to intercept/modify client-side JavaScript or server responses
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026