EIP-2026-117992

PRE-CVE

T-Mobile Internet Manager - Local Buffer Overflow (SEH)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117992. PoCs published by metacom.

AI-analyzed exploit summary This exploit leverages an SEH buffer overflow in T-Mobile Internet Manager by crafting a malicious UpdateCfg.ini file. The payload includes a structured header, junk data to trigger the overflow, an SEH bypass, and shellcode to execute arbitrary commands (e.g., calc.exe).

Description

T-Mobile Internet Manager - Local Buffer Overflow (SEH)

Exploits (1)

exploitdb WORKING POC VERIFIED
by metacom · pythonlocalwindows
https://www.exploit-db.com/exploits/35812

This exploit leverages an SEH buffer overflow in T-Mobile Internet Manager by crafting a malicious UpdateCfg.ini file. The payload includes a structured header, junk data to trigger the overflow, an SEH bypass, and shellcode to execute arbitrary commands (e.g., calc.exe).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: T-Mobile Internet Manager (TMO_PCV1.0.5B06)
No auth needed
Prerequisites: Access to the target system to place the malicious UpdateCfg.ini file in the specified directory · User interaction to trigger the update process in the T-Mobile Internet Manager application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026