EIP-2026-114739

PRE-CVE

Inso DynaWeb HTTPd 3.1/4.0.2/4.1 - Format String

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114739. PoCs published by ghandi.

AI-analyzed exploit summary This exploit targets a format string vulnerability in the DynaWeb HTTPD (dwhttpd) server, specifically in the nsapi_log_error() function. It bypasses authentication to retrieve a stack pointer from the error log and calculates the location of shellcode to execute arbitrary code, binding a shell to port 2001.

Description

Inso DynaWeb HTTPd 3.1/4.0.2/4.1 - Format String

Exploits (1)

exploitdb WORKING POC VERIFIED
by ghandi · cremotesolaris
https://www.exploit-db.com/exploits/21678

This exploit targets a format string vulnerability in the DynaWeb HTTPD (dwhttpd) server, specifically in the nsapi_log_error() function. It bypasses authentication to retrieve a stack pointer from the error log and calculates the location of shellcode to execute arbitrary code, binding a shell to port 2001.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: DynaWeb HTTPD (dwhttpd) versions 4.0.2a7a and 4.1a6 (as part of Solaris AnswerBook2)
No auth needed
Prerequisites: Network access to the target server · DynaWeb HTTPD running on port 8888 · Vulnerable version of dwhttpd
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026