DEV Community

jeffrey
jeffrey

Posted on

CVE-2026-75937 patch planning for Digi DAL OS fleets

CVE-2026-75937 patch planning for Digi DAL OS fleets

What the advisory says

Digi International disclosed CVE-2026-75937, an operating system command injection (CWE-78) in the
web administration service of Digi Accelerated Linux, the firmware known as DAL OS. The report
scores it 9.4 on CVSS 4.0. A single crafted HTTP POST to that interface runs arbitrary operating
system commands as root, and the attacker does not need to authenticate first.

Why the fixed builds matter more than the score

Affected firmware runs from DAL OS 21.8.24.139 through 26.7.90.14. Patched builds are 26.2.148.166 LTS and 26.7.90.15 for most IX, EX, TX and Connect IT models, 26.2.148.166 LTS for AnywhereUSB Plus and Connect EZ devices, and 26.9.10.28 for the XBee Hive gateways and IX15. The end-of-life 54xx, 63xx, IX14 and LR54 families will not receive a fix.
The patched set spans three branches, so an upgrade plan has to know which branch each device sits
on before it starts. By default only clients on the local LAN subnet reach the web interface. Digi warns that deployments which opened that interface to other subnets or to the WAN carry the higher, CVSS 10.0 risk profile. No public proof-of-concept and no confirmed in-the-wild exploitation had been reported when the advisory was published.

Ordering the work

Devices whose web administration interface answers beyond the local LAN come first, because they are
the ones an unauthenticated attacker can actually reach. After the firmware update, rotate the admin
password on every affected device and on any system that reused it. Where patching is not possible,
turn the web administration service off except while configuring the device. A Digi Remote Manager
template can switch that service back on, so the template has to be changed as well.

Exposure context

A ZoomEye International query for app="Digi" returned 47,984 matching assets on 2026-10-03. That
number describes Digi product fingerprints, not hosts confirmed to run a vulnerable DAL OS build, so
it sizes the fleet rather than the vulnerable subset.

References

Top comments (0)