EIP-2026-117773

PRE-CVE

Plantronics Hub 3.25.1 - Arbitrary File Read

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117773. PoCs published by Alaa Kachouh.

AI-analyzed exploit summary This exploit leverages an arbitrary file read vulnerability in Plantronics Hub 3.25.1 by placing a crafted 'MajorUpgrade.config' file in a specific directory, causing the target file to be copied to a predictable location. The PoC is straightforward and relies on the application's improper handling of the configuration file.

Description

Plantronics Hub 3.25.1 - Arbitrary File Read

Exploits (1)

exploitdb WORKING POC
by Alaa Kachouh · textlocalwindows
https://www.exploit-db.com/exploits/52011

This exploit leverages an arbitrary file read vulnerability in Plantronics Hub 3.25.1 by placing a crafted 'MajorUpgrade.config' file in a specific directory, causing the target file to be copied to a predictable location. The PoC is straightforward and relies on the application's improper handling of the configuration file.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Plantronics Hub for Windows version 3.25.1
No auth needed
Prerequisites: Write access to 'C:\ProgramData\Plantronics\Spokes3G' directory · Plantronics Hub 3.25.1 installed on Windows 10/11
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026