EIP-2026-103073

PRE-CVE

Axigen eMail Server 2.0.0b2 - 'pop3' Remote Format String

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103073. PoCs published by fuGich.

AI-analyzed exploit summary This exploit targets a format string vulnerability in Axigen eMail Server v2.0 (beta) POP3 service, leveraging a crafted format string to overwrite memory addresses and execute a bind shell on port 31337. The exploit includes shellcode for a bind shell and uses format string manipulation to achieve remote code execution.

Description

Axigen eMail Server 2.0.0b2 - 'pop3' Remote Format String

Exploits (1)

exploitdb WORKING POC VERIFIED
by fuGich · cremotelinux
https://www.exploit-db.com/exploits/3329

This exploit targets a format string vulnerability in Axigen eMail Server v2.0 (beta) POP3 service, leveraging a crafted format string to overwrite memory addresses and execute a bind shell on port 31337. The exploit includes shellcode for a bind shell and uses format string manipulation to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Axigen eMail Server v2.0 (beta)
No auth needed
Prerequisites: POP3 service with logType set to 'system' and logLevel with the 4th bit set
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026