EIP-2026-103128
PRE-CVEHafiye 1.0 - Remote Terminal Escape Sequence Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103128. PoCs published by Serkan Akpolat.
AI-analyzed exploit summary This exploit targets a terminal escape sequence injection vulnerability in Hafiye-1.0, allowing arbitrary command execution via crafted escape sequences. It sends malicious sequences to change the terminal title, ring the bell, or create a file in /root.
Description
Hafiye 1.0 - Remote Terminal Escape Sequence Injection
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Serkan Akpolat · cremotelinux
https://www.exploit-db.com/exploits/416
This exploit targets a terminal escape sequence injection vulnerability in Hafiye-1.0, allowing arbitrary command execution via crafted escape sequences. It sends malicious sequences to change the terminal title, ring the bell, or create a file in /root.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
Hafiye-1.0
No auth needed
Prerequisites:
Network access to the target service
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026