EIP-2026-102005
PRE-CVESitecom Home Storage Center - Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102005. PoCs published by Mattijs van Ommeren.
AI-analyzed exploit summary This advisory details a directory traversal vulnerability in Sitecom Home Storage Center devices (MD-253 and MD-254) running firmware up to version 2.4.17. The vulnerability allows unauthenticated attackers to read arbitrary files, including those containing administrative credentials, via a crafted URL targeting the `info.cgi` script.
Description
Sitecom Home Storage Center - Directory Traversal
Exploits (1)
This advisory details a directory traversal vulnerability in Sitecom Home Storage Center devices (MD-253 and MD-254) running firmware up to version 2.4.17. The vulnerability allows unauthenticated attackers to read arbitrary files, including those containing administrative credentials, via a crafted URL targeting the `info.cgi` script.