EIP-2026-103832
PRE-CVEABB Cylon Aspect 3.08.03 - Guest2Root Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103832. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an authenticated remote code execution vulnerability in ABB Cylon Aspect's firmware update mechanism. It uploads a crafted .bsx file via projectUpdateBSXFileProcess.php, which is then executed with root privileges due to a sudo misconfiguration, resulting in a root shell.
Description
ABB Cylon Aspect 3.08.03 - Guest2Root Privilege Escalation
Exploits (1)
This exploit leverages an authenticated remote code execution vulnerability in ABB Cylon Aspect's firmware update mechanism. It uploads a crafted .bsx file via projectUpdateBSXFileProcess.php, which is then executed with root privileges due to a sudo misconfiguration, resulting in a root shell.