← All Advisories

CVE-2026-75937

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-75937

Key Details

CVECVE-2026-75937
CVSS Score / Version9.4 (Critical) / CVSS v4.0
Updated2026-10-02
Affected productssee table below
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Digi InternationalIX Family
Digi InternationalEX Family
Digi InternationalTX Family
Digi InternationalConnect IT Family
Digi InternationalAnywhereUSB Plus Family
Digi InternationalConnect EZ Family
Digi InternationalXBee Hive Gateway
Digi InternationalXBee Hive Border Router for Wi-SUN
Digi InternationalDigi 54xx Family
Digi InternationalDigi 63xx Family
Digi InternationalDigi IX14
Digi InternationalDigi LR54 Family
SubsystemsGeneral OT
SectorsMultiple

What to Know

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. (NVD)

What to Do

Monitor Digi International's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-75937
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-75937