Retour à la veille

CVE-2026-105110

Publié : 8 octobre 2026
Modifié : 8 octobre 2026
Lien officiel NVD
Score CVSS
9.8
CRITICAL

Description détaillée

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Références et Patchs