Shell Command Injection Vulnerability in Modified uHTTPd Server for Network Devices
CVE-2026-63586
9.3CRITICAL
What is CVE-2026-63586?
The modified uHTTPd server, utilized in web-based management interfaces of certain network devices, is susceptible to a command injection vulnerability. The server improperly handles the HTTP Basic Authentication username, directly incorporating it into shell command strings without sufficient sanitization. Attackers can exploit this flaw by sending specially crafted usernames containing shell metacharacters, enabling them to escape the command context and execute arbitrary commands with root privileges. This poses significant risks to system integrity and security, allowing for unauthorized access and potential system compromise.
Affected Version(s)
IE-SR-2TX-WL 1.52 < 1.57
IE-SR-2TX-WL-4G-EU 1.67 < 1.74
IE-SR-2TX-WL-4G-US-V 1.67 < 1.74
