EIP-2026-102965

PRE-CVE

QNX PPPoEd 2.4/4.25/6.2 - Path Environment Variable Local Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102965. PoCs published by Julio Cesar Fort.

AI-analyzed exploit summary This exploit leverages a path manipulation vulnerability in QNX PPoEd to execute arbitrary commands with elevated privileges. By placing a malicious 'mount' script in /tmp and manipulating the PATH environment variable, the attacker tricks PPoEd into executing the script as root, resulting in a root shell.

Description

QNX PPPoEd 2.4/4.25/6.2 - Path Environment Variable Local Command Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by Julio Cesar Fort · textlocallinux
https://www.exploit-db.com/exploits/24570

This exploit leverages a path manipulation vulnerability in QNX PPoEd to execute arbitrary commands with elevated privileges. By placing a malicious 'mount' script in /tmp and manipulating the PATH environment variable, the attacker tricks PPoEd into executing the script as root, resulting in a root shell.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: QNX PPoEd (version not specified, but likely affects multiple versions)
No auth needed
Prerequisites: Access to a system with QNX PPoEd installed · Ability to write to /tmp · Ability to execute /usr/sbin/pppoed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026