Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109883. PoCs published by lumut--.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in NetLink's upload.php, allowing attackers to upload malicious files (e.g., PHP shells) to the server. The vulnerability arises due to insufficient file type validation and authentication checks.
Description
NetLink - Arbitrary File Upload
Exploits (1)
exploitdb
WORKING POC
by lumut-- · phpwebappsphp
https://www.exploit-db.com/exploits/16088
This exploit demonstrates an arbitrary file upload vulnerability in NetLink's upload.php, allowing attackers to upload malicious files (e.g., PHP shells) to the server. The vulnerability arises due to insufficient file type validation and authentication checks.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
NetLink (version not specified)
Auth required
Prerequisites:
Access to the upload.php endpoint · Valid session credentials
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026