EIP-2026-102085

PRE-CVE

Ubee EVW3200 - Multiple Persistent Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102085. PoCs published by Jeroen - IT Nerdbox.

AI-analyzed exploit summary This exploit demonstrates multiple persistent XSS vulnerabilities in Ubee EVW3200 devices. The payloads are injected into the SSID, Device name, or VPN Tunnel name fields, triggering JavaScript execution when rendered in the web interface.

Description

Ubee EVW3200 - Multiple Persistent Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Jeroen - IT Nerdbox · textwebappshardware
https://www.exploit-db.com/exploits/32237

This exploit demonstrates multiple persistent XSS vulnerabilities in Ubee EVW3200 devices. The payloads are injected into the SSID, Device name, or VPN Tunnel name fields, triggering JavaScript execution when rendered in the web interface.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Ubee EVW3200 (All versions)
Auth required
Prerequisites: Access to the device's web configuration interface · Valid credentials for authentication
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026