OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-105110 (CVSS 9.3)

NVD · officialPublished Oct 8, 2026Risk 50/100

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source