cbcvebase.
CVE-2026-75937
published 2026-10-02

CVE-2026-75937: A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands…

PriorityP266critical9.4CVSS 4.0
AVAACLATNPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.53%
42.8th percentile
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

Affected

12 ranges
VendorProductVersion rangeFixed in
digi_internationalanywhereusb_plus_family21.8.24.139 – 26.7.90.14—
digi_internationalconnect_ez_family21.8.24.139 – 26.7.90.14—
digi_internationalconnect_it_family21.8.24.139 – 26.7.90.14—
digi_internationaldigi_54xx_family<= 21.8.24.139—
digi_internationaldigi_63xx_family21.8.24.139 – 22.5.50.66—
digi_internationaldigi_ix1421.8.24.139 – 22.5.50.62—
digi_internationaldigi_lr54_family21.8.24.139 – 23.12.1.56—
digi_internationalex_family21.8.24.139 – 26.7.90.14—
digi_internationalix_family21.8.24.139 – 26.7.90.14—
digi_internationaltx_family21.8.24.139 – 26.7.90.14—
digi_internationalxbee_hive_border_router_for_wi-sun21.8.24.139 – 26.7.90.14—
digi_internationalxbee_hive_gateway21.8.24.139 – 26.7.90.14—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.