EIP-2026-109125
PRE-CVELifeSize UVC 1.2.6 - (Authenticated) Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109125. PoCs published by Brandon Perry.
AI-analyzed exploit summary This exploit demonstrates authenticated remote command execution (RCE) in LifeSize UVC 1.2.6 via command injection in the diagnose/ping, diagnose/trace, and diagnose/dns endpoints. The payload is injected into the destination_ip parameter, resulting in command execution as the www-data user.
Description
LifeSize UVC 1.2.6 - (Authenticated) Remote Code Execution
Exploits (1)
This exploit demonstrates authenticated remote command execution (RCE) in LifeSize UVC 1.2.6 via command injection in the diagnose/ping, diagnose/trace, and diagnose/dns endpoints. The payload is injected into the destination_ip parameter, resulting in command execution as the www-data user.