{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108576", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-10-10T15:41:51.290Z", "datePublished": "2026-10-11T12:15:13.822Z", "dateUpdated": "2026-10-11T12:15:13.822Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-10-11T12:15:13.822Z" }, "title": "TOZED X300 IPPingDiagnostics process_ping os command injection", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-78", "lang": "en", "description": "OS Command Injection" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-77", "lang": "en", "description": "Command Injection" } ] } ], "affected": [ { "vendor": "TOZED", "product": "X300", "versions": [ { "version": "6.01.0", "status": "affected" }, { "version": "6.01.1", "status": "affected" }, { "version": "6.01.2", "status": "affected" }, { "version": "6.01.3", "status": "affected" } ], "cpes": [ "cpe:2.3:a:tozed:x300:*:*:*:*:*:*:*:*" ], "modules": [ "IPPingDiagnostics Handler" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was found in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 10, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X", "baseSeverity": "CRITICAL" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 10, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R", "baseSeverity": "CRITICAL" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 10, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R", "baseSeverity": "CRITICAL" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 10, "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:ND/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-10-10T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-10-10T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-10-10T17:47:19.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "danish1162 (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/416233", "name": "VDB-416233 | TOZED X300 IPPingDiagnostics process_ping os command injection", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/416233/cti", "name": "VDB-416233 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-108576", "name": "CVE-2026-108576 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/956290", "name": "Submit #956290 | Tozed Kangwei ZLT X300 6.01.3 Command Injection", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/danish1162/CVE-2026-2035703-x300/security/advisories/GHSA-qcpp-vfr2-v242", "tags": [ "related" ] } ], "x_generator": [ "VulDB PVTS v202610" ] } } }