EIP-2026-102965
PRE-CVEQNX PPPoEd 2.4/4.25/6.2 - Path Environment Variable Local Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102965. PoCs published by Julio Cesar Fort.
AI-analyzed exploit summary This exploit leverages a path manipulation vulnerability in QNX PPoEd to execute arbitrary commands with elevated privileges. By placing a malicious 'mount' script in /tmp and manipulating the PATH environment variable, the attacker tricks PPoEd into executing the script as root, resulting in a root shell.
Description
QNX PPPoEd 2.4/4.25/6.2 - Path Environment Variable Local Command Execution
Exploits (1)
This exploit leverages a path manipulation vulnerability in QNX PPoEd to execute arbitrary commands with elevated privileges. By placing a malicious 'mount' script in /tmp and manipulating the PATH environment variable, the attacker tricks PPoEd into executing the script as root, resulting in a root shell.