CVE-2026-75937 PUBLISHED

OS Command Injection in Digi Accelerated Linux (DAL OS)

Assigner: Digi
Reserved: 18.08.2026 Published: 02.10.2026 Updated: 02.10.2026

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Digi International
Product IX Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product EX Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product TX Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product Connect IT Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product AnywhereUSB Plus Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product Connect EZ Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product XBee Hive Gateway
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product XBee Hive Border Router for Wi-SUN
Versions Default: unaffected
  • affected from 21.8.24.139 to 26.7.90.14 (incl.)
Vendor Digi International
Product Digi 54xx Family
Versions Default: unaffected
  • affected from 0 to 21.8.24.139 (incl.)
Vendor Digi International
Product Digi 63xx Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 22.5.50.66 (incl.)
Vendor Digi International
Product Digi IX14
Versions Default: unaffected
  • affected from 21.8.24.139 to 22.5.50.62 (incl.)
Vendor Digi International
Product Digi LR54 Family
Versions Default: unaffected
  • affected from 21.8.24.139 to 23.12.1.56 (incl.)

Credits

  • 美团众包骑手:键盘手欧多克 finder

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE