OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-108576 (CVSS 10.0)

NVD · officialPublished Oct 11, 2026Risk 50/100

A vulnerability was found in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS
10.0
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source