Sceawere

Vulnerability Detail

CVE-2026-105110UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OS Command Injection in Iskratel

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Iskratel
Product
Innbox
Attack Type
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-08T09:16:40.930Z",
  "pubdate": "2026-10-08T09:16:40.930Z",
  "executiveSummary": "The vulnerability identified in Iskratel Innbox GPON ONT devices is an OS Command Injection flaw located within the login.xgi CGI endpoint. This critical security defect allows an unauthenticated, remote attacker to execute arbitrary system commands with root-level privileges on the target device.\nThe vulnerability stems from improper neutralization of special elements used in the 'CLI' parameter passed to the CGI script. By injecting malicious payloads into this input field, an attacker can bypass standard security controls and interact directly with the underlying operating system.\nThe impact of this vulnerability is severe, as it grants full control over the affected network terminal. An attacker successfully exploiting this flaw could potentially compromise the confidentiality, integrity, and availability of the device, leading to full system takeover, unauthorized access to network configurations, traffic interception, or the inclusion of the device into a botnet. Given that exploitation does not require prior authentication, the risk to exposed devices is high, necessitating immediate defensive measures to limit network exposure.",
  "technicalDetails": "The vulnerability resides in the 'login.xgi' CGI binary, which serves as a component of the web management interface for Iskratel Innbox GPON ONT units. The primary flaw is an OS Command Injection vulnerability triggered through the 'CLI' parameter.\nRoot Cause: The CGI application fails to perform adequate input validation or sanitization on data received via the 'CLI' parameter. When the application processes this input, it passes the unsanitized string directly to a system-level shell or function (such as system(), popen(), or equivalent wrappers), allowing the injection of arbitrary shell metacharacters (e.g., ;, |, &&, `).\nExploitation Method: An unauthenticated remote attacker initiates an HTTP request (typically GET or POST) to the vulnerable endpoint '/login.xgi'. The attacker crafts a request where the 'CLI' parameter is appended with shell-executable instructions. For instance, a payload designed to ping an external server or spawn a reverse shell would be processed by the device's shell interpreter.\nAttack Flow: 1. The attacker identifies the publicly reachable web interface of the Iskratel Innbox device. 2. The attacker sends a specially crafted HTTP request to the login.xgi endpoint. 3. The web server passes the 'CLI' parameter value to the vulnerable CGI script without filtering. 4. The CGI script improperly concatenates this value into a system command string. 5. The device's underlying operating system executes the command with root user privileges, effectively bypassing the intended logical constraints of the management interface.\nPrivilege and Exposure: The vulnerability is exploitable remotely over the network without the requirement of valid credentials. Because the CGI binary runs with root-level process permissions, any command executed by the attacker inherits these privileges, leading to complete system compromise.\nPost-Exploitation: Once arbitrary code execution is achieved, an attacker can modify device firmware, alter routing tables to facilitate man-in-the-middle attacks, exfiltrate sensitive configuration files, or establish persistent backdoors. Due to the nature of GPON ONT devices being edge gateways, this compromise effectively threatens the entire downstream local area network."
}
CVE-2026-105110: OS Command Injection in Iskratel (CRITICAL Severity, CVSS: 9.8) | Sceawere