EIP-2026-118298

PRE-CVE

Avirt Gateway Suite 3.3/3.3 a/3.5 - Directory Creation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118298. PoCs published by Jesús López de Aguileta.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in aVirt Mail Server via the RCPT TO command, allowing an attacker to create arbitrary directories on the server's filesystem. The PoC uses a simple telnet interaction to trigger the flaw without requiring authentication.

Description

Avirt Gateway Suite 3.3/3.3 a/3.5 - Directory Creation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jesús López de Aguileta · textremotewindows
https://www.exploit-db.com/exploits/19589

This exploit demonstrates a directory traversal vulnerability in aVirt Mail Server via the RCPT TO command, allowing an attacker to create arbitrary directories on the server's filesystem. The PoC uses a simple telnet interaction to trigger the flaw without requiring authentication.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: aVirt Mail Server
No auth needed
Prerequisites: network access to the SMTP port (25)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026