Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-118402. PoCs published by demonalex.
AI-analyzed exploit summary This Perl script exploits a directory traversal vulnerability in Deepin TFTP Server v1.25 by sending maliciously crafted filenames via TFTP to write or retrieve files outside the intended directory. The PoC tests multiple traversal sequences and confirms successful exploitation.
Description
Deepin TFTP Server 1.25 - Directory Traversal
Exploits (1)
exploitdb
WORKING POC
by demonalex · perlremotewindows
https://www.exploit-db.com/exploits/14779
This Perl script exploits a directory traversal vulnerability in Deepin TFTP Server v1.25 by sending maliciously crafted filenames via TFTP to write or retrieve files outside the intended directory. The PoC tests multiple traversal sequences and confirms successful exploitation.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Deepin TFTP Server v1.25
No auth needed
Prerequisites:
Network access to the TFTP server · TFTP client (tftp.exe)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026