EIP-2026-116242

PRE-CVE

SIEMENS Solid Edge ST4/ST5 SEListCtrlX - ActiveX SetItemReadOnly Arbitrary Memory Rewrite Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116242. PoCs published by rgod.

AI-analyzed exploit summary The exploit demonstrates an arbitrary memory write vulnerability in Siemens Solid Edge ST4/ST5 via the SEListCtrlX ActiveX control's SetItemReadOnly method, allowing NULL or 0x08 byte writes to arbitrary memory addresses, leading to potential RCE.

Description

SIEMENS Solid Edge ST4/ST5 SEListCtrlX - ActiveX SetItemReadOnly Arbitrary Memory Rewrite Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by rgod · textdoswindows
https://www.exploit-db.com/exploits/25712

The exploit demonstrates an arbitrary memory write vulnerability in Siemens Solid Edge ST4/ST5 via the SEListCtrlX ActiveX control's SetItemReadOnly method, allowing NULL or 0x08 byte writes to arbitrary memory addresses, leading to potential RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Siemens Solid Edge ST4/ST5
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 7/8
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026