← Back to overview

A vulnerability has been identified in MegaEase EaseProbe up to version 2.3.0, affecting the realIP function in web/server.go within the Middleware component. The flaw allows manipulation of HTTP headers X-Forwarded-For, X-Real-IP, and True-Client-IP to bypass access controls improperly. The attack can be initiated remotely without requiring physical access. A public exploit has been published and is available for use. The vendor was contacted prior to disclosure but did not respond. This improper trust of client-supplied headers for IP resolution is a classic IP spoofing vulnerability enabling unauthorized access.

Affected products

  • MegaEase EaseProbe 2.3.0

Related CVE's

  • CVE-2026-82815

Categories

  • Identity & Access
  • Web Technologies