Command Injection Vulnerability in Linux OS Devices by Specific Vendor
CVE-2026-22317
7.2HIGH
What is CVE-2026-22317?
A command injection vulnerability exists in the Root CA certificate transfer workflow of specific Linux OS devices. This flaw enables an attacker with high privileges to execute arbitrary commands on the machine by sending specially crafted HTTP POST requests. Successful exploitation can compromise the integrity and security of the affected device, posing significant risks to the underlying operating system and its operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FL NAT 2008 0.0.0 < 3.53
FL NAT 2208 0.0.0 < 3.53
FL NAT 2304-2GC-2SFP 0.0.0 < 3.53
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Quagliarella from Nozomi Networks
