Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-106986. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates a local file disclosure vulnerability in EyeLock nano NXT due to improper input validation in the 'logdownload.php' script. Attackers can read arbitrary files by manipulating the 'path' parameter.
Description
EyeLock nano NXT 3.5 - Local File Disclosure
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/40227
The exploit demonstrates a local file disclosure vulnerability in EyeLock nano NXT due to improper input validation in the 'logdownload.php' script. Attackers can read arbitrary files by manipulating the 'path' parameter.
Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
EyeLock nano NXT Firmware 3.05.1193 (ICM: 3.5.1) and earlier
No auth needed
Prerequisites:
Network access to the vulnerable device
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026