CVE-2026-75937
published 2026-10-02CVE-2026-75937: A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands…
PriorityP266critical9.4CVSS 4.0
AVAACLATNPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.53%
42.8th percentile
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| digi_international | anywhereusb_plus_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | connect_ez_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | connect_it_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | digi_54xx_family | <= 21.8.24.139 | — |
| digi_international | digi_63xx_family | 21.8.24.139 – 22.5.50.66 | — |
| digi_international | digi_ix14 | 21.8.24.139 – 22.5.50.62 | — |
| digi_international | digi_lr54_family | 21.8.24.139 – 23.12.1.56 | — |
| digi_international | ex_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | ix_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | tx_family | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | xbee_hive_border_router_for_wi-sun | 21.8.24.139 – 26.7.90.14 | — |
| digi_international | xbee_hive_gateway | 21.8.24.139 – 26.7.90.14 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Digi International AnywhereUSB Plus Family Web Administration Interface os command injection
vuldb·2026-10-02·CVSS 9.4
CVE-2026-75937 [CRITICAL] Digi International AnywhereUSB Plus Family Web Administration Interface os command injection
A vulnerability classified as very critical has been found in Digi International AnywhereUSB Plus Family, Connect EZ Family, Connect IT Family, Connect IT Family, EX Family, IX Family, IX14, LR54 Family, TX Family, XBee Hive Border Router for Wi-SUN and XBee Hive Gateway. This affects an unknown function of the component Web Administration Interface. Performing a manipulation results in os command injection.
This vulnerability was named CVE-2026-75937. The attack may be initiated remotely. There is no available exploit.
GHSA
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device.
ghsa_unreviewed·2026-10-02
CVE-2026-75937 [CRITICAL] CWE-78 A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device.
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-02
Published