Remote Command Execution Vulnerability in Digi Embedded System Software
CVE-2026-75937
9.4CRITICAL
Key Information:
- Vendor
Digi International
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-75937?
This vulnerability allows an unauthenticated attacker to send specially crafted HTTP POST requests to the web administration interface of Digi Embedded System Software. If exploited, this can result in the execution of arbitrary operating system commands with root privileges, potentially compromising system integrity. Users are advised to disable the web server when not in use to minimize exposure.
Affected Version(s)
AnywhereUSB Plus Family 21.8.24.139 <= 26.7.90.14
Connect EZ Family 21.8.24.139 <= 26.7.90.14
Connect IT Family 21.8.24.139 <= 26.7.90.14
