EIP-2026-104248

PRE-CVE

Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104248. PoCs published by forsec.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Fibaro's liliSetDeviceCommand.php endpoint to achieve remote code execution (RCE). It crafts a malicious payload that writes a reverse shell script to a tar archive, encodes it in base64, and executes it via sudo update --manual, resulting in a root shell.

Description

Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by forsec · pythonwebappsmultiple
https://www.exploit-db.com/exploits/42884

This exploit leverages a command injection vulnerability in Fibaro's liliSetDeviceCommand.php endpoint to achieve remote code execution (RCE). It crafts a malicious payload that writes a reverse shell script to a tar archive, encodes it in base64, and executes it via sudo update --manual, resulting in a root shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Fibaro Home Center (version not specified)
No auth needed
Prerequisites: Network access to the target · Target must have the vulnerable endpoint exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026