EIP-2026-118402

PRE-CVE

Deepin TFTP Server 1.25 - Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118402. PoCs published by demonalex.

AI-analyzed exploit summary This Perl script exploits a directory traversal vulnerability in Deepin TFTP Server v1.25 by sending maliciously crafted filenames via TFTP to write or retrieve files outside the intended directory. The PoC tests multiple traversal sequences and confirms successful exploitation.

Description

Deepin TFTP Server 1.25 - Directory Traversal

Exploits (1)

exploitdb WORKING POC
by demonalex · perlremotewindows
https://www.exploit-db.com/exploits/14779

This Perl script exploits a directory traversal vulnerability in Deepin TFTP Server v1.25 by sending maliciously crafted filenames via TFTP to write or retrieve files outside the intended directory. The PoC tests multiple traversal sequences and confirms successful exploitation.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Deepin TFTP Server v1.25
No auth needed
Prerequisites: Network access to the TFTP server · TFTP client (tftp.exe)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026