EIP-2026-115181

PRE-CVE

Easewe FTP OCX ActiveX Control 4.5.0.9 - 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115181. PoCs published by High-Tech Bridge SA.

AI-analyzed exploit summary The exploit demonstrates multiple insecure method vulnerabilities in the Easewe FTP OCX ActiveX control, allowing arbitrary command execution, file creation, and deletion via VBScript. The PoC leverages methods like Execute, Run, CreateLocalFile, and DeleteLocalFile.

Description

Easewe FTP OCX ActiveX Control 4.5.0.9 - 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · htmldoswindows
https://www.exploit-db.com/exploits/35876

The exploit demonstrates multiple insecure method vulnerabilities in the Easewe FTP OCX ActiveX control, allowing arbitrary command execution, file creation, and deletion via VBScript. The PoC leverages methods like Execute, Run, CreateLocalFile, and DeleteLocalFile.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Easewe FTP OCX ActiveX control 4.5.0.9
No auth needed
Prerequisites: Victim must open the malicious HTML file in a browser with ActiveX enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026