DEV Community

yutianle
yutianle

Posted on

CVE-2026-75937: why a management interface decides the risk

CVE-2026-75937: why a management interface decides the risk

Overview

Digi Accelerated Linux ships the web administration service used to configure the IX, EX and TX
cellular routers, the Connect IT and Connect EZ console servers, the AnywhereUSB hubs and the XBee
gateways. CVE-2026-75937 lives in that service. A crafted HTTP POST runs operating system commands as
root without any prior authentication, and the disclosure scores the issue 9.4 on CVSS 4.0.

The interface is the control

By default only clients on the local LAN subnet reach the web interface. Digi warns that deployments which opened that interface to other subnets or to the WAN carry the higher, CVSS 10.0 risk profile. No public proof-of-concept and no confirmed in-the-wild exploitation had been reported when the advisory was published.
That single configuration choice separates a device that is only reachable from its own subnet from
one that any internet client can address. Digi associates the wider exposure with the higher, CVSS
10.0 figure.

Technical mechanism

The weakness is an operating system command injection, CWE-78. Digi's advisory describes a
specifically crafted HTTP POST request to the web administration interface that results in arbitrary
command execution with root privileges.

Affected firmware

Affected firmware runs from DAL OS 21.8.24.139 through 26.7.90.14. Patched builds are 26.2.148.166 LTS and 26.7.90.15 for most IX, EX, TX and Connect IT models, 26.2.148.166 LTS for AnywhereUSB Plus and Connect EZ devices, and 26.9.10.28 for the XBee Hive gateways and IX15. The end-of-life 54xx, 63xx, IX14 and LR54 families will not receive a fix.

Exposure context

A ZoomEye International query for app="Digi" returned 47,984 matching assets on 2026-10-03. Those
matches identify Digi products by fingerprint. They do not establish that any host runs a vulnerable
DAL OS version or that its administration service is open.

Remediation

Move to the fixed build for the relevant model branch, then rotate the administrative password. Where
that is impossible, close the web administration service outside configuration windows and audit the
Digi Remote Manager template so it does not reopen the service.

References

Top comments (0)