Shell Command Injection Vulnerability in Modified uHTTPd Server for Network Devices
CVE-2026-63586

9.3CRITICAL

What is CVE-2026-63586?

The modified uHTTPd server, utilized in web-based management interfaces of certain network devices, is susceptible to a command injection vulnerability. The server improperly handles the HTTP Basic Authentication username, directly incorporating it into shell command strings without sufficient sanitization. Attackers can exploit this flaw by sending specially crafted usernames containing shell metacharacters, enabling them to escape the command context and execute arbitrary commands with root privileges. This poses significant risks to system integrity and security, allowing for unauthorized access and potential system compromise.

Affected Version(s)

IE-SR-2TX-WL 1.52 < 1.57

IE-SR-2TX-WL-4G-EU 1.67 < 1.74

IE-SR-2TX-WL-4G-US-V 1.67 < 1.74

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.