EIP-2026-102090
PRE-CVEuc-http Daemon - Local File Inclusion / Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102090. PoCs published by Project Insecurity.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) and Directory Traversal vulnerability in uc-httpd, allowing attackers to read arbitrary files or list directories on vulnerable IoT devices. The PoC sends a crafted HTTP GET request with traversal sequences to access sensitive files like /etc/passwd.
Description
uc-http Daemon - Local File Inclusion / Directory Traversal
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) and Directory Traversal vulnerability in uc-httpd, allowing attackers to read arbitrary files or list directories on vulnerable IoT devices. The PoC sends a crafted HTTP GET request with traversal sequences to access sensitive files like /etc/passwd.