Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-102128. PoCs published by Gregory Smiley.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Xfinity Gateway's network diagnostic tools. The `destination_address` parameter in a POST request to `/actionHandler/ajax_network_diagnostic_tools.php` allows arbitrary command execution, as shown by injecting a ping command to an attacker-controlled IP.
Description
Xfinity Gateway - Remote Code Execution
Exploits (1)
This exploit demonstrates a command injection vulnerability in Xfinity Gateway's network diagnostic tools. The `destination_address` parameter in a POST request to `/actionHandler/ajax_network_diagnostic_tools.php` allows arbitrary command execution, as shown by injecting a ping command to an attacker-controlled IP.