CVE-2026-75937
OS Command Injection in Digi Accelerated Linux (DAL OS)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
| CWE | CWE-78 |
| Vendor | digi international |
| Product | ix family |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for digi international ix family
Be the first to know when new unknown vulnerabilities affecting digi international ix family are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Digi International / IX Family
21.8.24.139 ≤ 26.7.90.14
Digi International / EX Family
21.8.24.139 ≤ 26.7.90.14
Digi International / TX Family
21.8.24.139 ≤ 26.7.90.14
Digi International / Connect IT Family
21.8.24.139 ≤ 26.7.90.14
Digi International / AnywhereUSB Plus Family
21.8.24.139 ≤ 26.7.90.14
Digi International / Connect EZ Family
21.8.24.139 ≤ 26.7.90.14
Digi International / XBee Hive Gateway
21.8.24.139 ≤ 26.7.90.14
Digi International / XBee Hive Border Router for Wi-SUN
21.8.24.139 ≤ 26.7.90.14
Digi International / Digi 54xx Family
0 ≤ 21.8.24.139
Digi International / Digi 63xx Family
21.8.24.139 ≤ 22.5.50.66
Digi International / Digi IX14
21.8.24.139 ≤ 22.5.50.62
Digi International / Digi LR54 Family
21.8.24.139 ≤ 23.12.1.56
Credits
美团众包骑手:键盘手欧多克