CVE-2026-75937

Summary

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

Affected Software

VendorProductVersion RangeStatus
Digi InternationalIX Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalEX Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalTX Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalConnect IT Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalAnywhereUSB Plus Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalConnect EZ Family21.8.24.139 <= 26.7.90.14affected
Digi InternationalXBee Hive Gateway21.8.24.139 <= 26.7.90.14affected
Digi InternationalXBee Hive Border Router for Wi-SUN21.8.24.139 <= 26.7.90.14affected
Digi InternationalDigi 54xx Family0 <= 21.8.24.139affected
Digi InternationalDigi 63xx Family21.8.24.139 <= 22.5.50.66affected
Digi InternationalDigi IX1421.8.24.139 <= 22.5.50.62affected
Digi InternationalDigi LR54 Family21.8.24.139 <= 23.12.1.56affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References