EIP-2026-102085
PRE-CVEUbee EVW3200 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102085. PoCs published by Jeroen - IT Nerdbox.
AI-analyzed exploit summary This exploit demonstrates multiple persistent XSS vulnerabilities in Ubee EVW3200 devices. The payloads are injected into the SSID, Device name, or VPN Tunnel name fields, triggering JavaScript execution when rendered in the web interface.
Description
Ubee EVW3200 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
by Jeroen - IT Nerdbox · textwebappshardware
https://www.exploit-db.com/exploits/32237
This exploit demonstrates multiple persistent XSS vulnerabilities in Ubee EVW3200 devices. The payloads are injected into the SSID, Device name, or VPN Tunnel name fields, triggering JavaScript execution when rendered in the web interface.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Ubee EVW3200 (All versions)
Auth required
Prerequisites:
Access to the device's web configuration interface · Valid credentials for authentication
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026