EIP-2026-102015

PRE-CVE

Solare Datensysteme Solar-Log Devices 2.8.4-56/3.5.2-85 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102015. PoCs published by SEC Consult.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Solare Datensysteme GmbH Solar-Log devices, including unauthenticated configuration download, CSRF, arbitrary file upload, information disclosure, and network reconfiguration. The PoC provides clear examples of HTTP and UDP requests to exploit these issues.

Description

Solare Datensysteme Solar-Log Devices 2.8.4-56/3.5.2-85 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by SEC Consult · textwebappshardware
https://www.exploit-db.com/exploits/41671

The exploit demonstrates multiple vulnerabilities in Solare Datensysteme GmbH Solar-Log devices, including unauthenticated configuration download, CSRF, arbitrary file upload, information disclosure, and network reconfiguration. The PoC provides clear examples of HTTP and UDP requests to exploit these issues.

Classification
Working Poc 100%
Attack Type
Info Leak | Auth Bypass | Xss | Dos | Other
Complexity
Trivial
Reliability
Reliable
Target: Solare Datensysteme GmbH Solar-Log 250/300/500/800e/1000/1000 PM+/1200/2000, Firmware 2.8.4-56 / 3.5.2-85
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026