EIP-2026-119067

PRE-CVE

Quick Tftp Server Pro 2.1 - Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119067. PoCs published by Yakir Wizman.

AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in Quick Tftp Server Pro v2.1, allowing an attacker to read and write files outside the intended directory using the GET and PUT commands. The provided example shows successful retrieval of the boot.ini file via directory traversal sequences.

Description

Quick Tftp Server Pro 2.1 - Directory Traversal

Exploits (1)

exploitdb WORKING POC
by Yakir Wizman · textremotewindows
https://www.exploit-db.com/exploits/15437

This exploit demonstrates a path traversal vulnerability in Quick Tftp Server Pro v2.1, allowing an attacker to read and write files outside the intended directory using the GET and PUT commands. The provided example shows successful retrieval of the boot.ini file via directory traversal sequences.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Quick Tftp Server Pro v2.1
No auth needed
Prerequisites: Network access to the TFTP server · TFTP client utility
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026