CVE-2026-105110 PUBLISHED

Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter

Assigner: TuranSec
Reserved: 03.10.2026 Published: 08.10.2026 Updated: 08.10.2026

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVSS Score: 9.3

Product Status

Vendor Iskratel
Product Innbox
Versions Default: affected

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE
  • CWE-306 Missing Authentication for Critical Function CWE

Impacts

  • An unauthenticated remote attacker can execute arbitrary commands as root, leading to full device compromise including credential extraction, configuration tampering, and persistent backdoor installation.