EIP-2026-118501

PRE-CVE

EDraw Office Viewer 5.4 - 'HttpDownloadFile()' Insecure Method

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118501. PoCs published by Cyber-Zone.

AI-analyzed exploit summary This exploit targets an insecure method in Edraw Office Viewer Component v5.4, specifically the HttpDownloadFile() function, which allows arbitrary file download to the victim's system. The PoC uses VBScript to trigger the download of a file from a remote server to a local path.

Description

EDraw Office Viewer 5.4 - 'HttpDownloadFile()' Insecure Method

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cyber-Zone · htmlremotewindows
https://www.exploit-db.com/exploits/7762

This exploit targets an insecure method in Edraw Office Viewer Component v5.4, specifically the HttpDownloadFile() function, which allows arbitrary file download to the victim's system. The PoC uses VBScript to trigger the download of a file from a remote server to a local path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Edraw Office Viewer Component v5.4
No auth needed
Prerequisites: Victim must open the malicious HTML file in a browser with the vulnerable component installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026