Sceawere

Vulnerability Detail

CVE-2026-108576UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TOZED X300 OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
4h ago
Vendor
TOZED
Product
X300
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-11T13:17:13.067Z",
  "pubdate": "2026-10-11T13:17:13.067Z",
  "executiveSummary": "A critical OS command injection vulnerability has been identified in the TOZED X300 router, specifically within the IPPingDiagnostics Handler component.\nThe vulnerability originates from improper neutralization of user-supplied input within the 'Host' argument passed to the 'process_ping' function.\nSuccessful exploitation allows a remote, unauthenticated attacker to execute arbitrary operating system commands with elevated privileges on the target device.\nThe risk is severe as it enables full device compromise, potentially facilitating unauthorized network access, data interception, or the integration of the router into a botnet.\nThe affected versions include all firmware up to and including 6.01.3.\nDespite disclosure attempts, the vendor has not provided a patch or formal response, leaving devices exposed to active exploitation.\nDeployment in sensitive environments is discouraged without compensating controls, as no official software remediation is currently available.",
  "technicalDetails": "The vulnerability resides within the IPPingDiagnostics Handler, which provides diagnostic functionality for network troubleshooting. Specifically, the 'process_ping' function fails to perform adequate input validation or sanitization on the 'Host' argument provided by the user interface or API.\nThe root cause is a classic command injection pattern where the application constructs a system-level command string by concatenating the 'Host' input directly into a shell execution context, such as a 'ping' utility call. By injecting shell metacharacters (e.g., ';', '&', '|', '`'), an attacker can escape the intended command string and execute arbitrary system instructions.\nThe attack flow begins with an attacker sending a crafted network request (such as an HTTP request containing the malicious 'Host' parameter) to the device's management interface. Because the 'process_ping' function handles this input without filtering, the shell environment interprets the injected payload as a sequence of legitimate commands.\nThe 'process_ping' function executes the resulting command with the privileges of the web service user, which, in embedded router firmware, is typically the root user. Consequently, the attacker achieves full administrative control over the underlying Linux-based operating system.\nThere are no requirements for authentication or elevated privileges prior to initiating the exploit, making it feasible for remote attackers to trigger the vulnerability over the network if the diagnostic interface is exposed. The payload behavior is limited only by the attacker's intent and the available binaries on the system; common post-exploitation activities include the deployment of reverse shells, credential harvesting, persistence establishment via startup scripts, or the modification of device routing tables to perform man-in-the-middle attacks.\nThis vulnerability highlights a failure in the secure development lifecycle of the TOZED X300 firmware, specifically regarding input handling in administrative utilities. As the component is responsible for diagnostic tasks, it is frequently reachable via the web-based management portal, significantly increasing the attack surface."
}
CVE-2026-108576: TOZED X300 OS Command Injection (CRITICAL Severity, CVSS: 10.0) | Sceawere