Remote Command Execution Vulnerability in Digi Embedded System Software
CVE-2026-75937

9.4CRITICAL

Key Information:

Vendor
CVE Published:
2 October 2026

What is CVE-2026-75937?

This vulnerability allows an unauthenticated attacker to send specially crafted HTTP POST requests to the web administration interface of Digi Embedded System Software. If exploited, this can result in the execution of arbitrary operating system commands with root privileges, potentially compromising system integrity. Users are advised to disable the web server when not in use to minimize exposure.

Affected Version(s)

AnywhereUSB Plus Family 21.8.24.139 <= 26.7.90.14

Connect EZ Family 21.8.24.139 <= 26.7.90.14

Connect IT Family 21.8.24.139 <= 26.7.90.14

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

美团众包骑手:键盘手欧多克
.