CVE-2026-108576 | TOZED X300 up to 6.01.3 IPPingDiagnostics process_ping Host os command injection

SecurityVulns

A vulnerability described as very critical has been identified in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in os command injection.

This vulnerability is reported as CVE-2026-108576. The attack can be launched remotely. No exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More