« Volver al listado

CVE-2026-75937

Estado: Pendiente de análisisCrítica (9.4)—

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A sin PR permite red adyacente sin privilegios (T1210). Ejecución de comandos OS con root (CWE-78, descripción explícita) da T1059 primario y T1068 secundario por elevación a privilegios root.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-75937",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-75937",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-10-03T15:47:40.910645Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "e8a6bb0b-e373-42b1-a5de-93e314325576",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 9.4,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "CRITICAL",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "e8a6bb0b-e373-42b1-a5de-93e314325576",
      "affectedData": [
        {
          "vendor": "Digi International",
          "product": "IX Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "EX Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "TX Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Connect IT Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "AnywhereUSB Plus Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Connect EZ Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "XBee Hive Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "XBee Hive Border Router for Wi-SUN",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "26.7.90.14"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Digi 54xx Family",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "21.8.24.139"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Digi 63xx Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "22.5.50.66"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Digi IX14",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "22.5.50.62"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Digi International",
          "product": "Digi LR54 Family",
          "versions": [
            {
              "status": "affected",
              "version": "21.8.24.139",
              "versionType": "custom",
              "lessThanOrEqual": "23.12.1.56"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-02T21:16:56.337",
  "references": [
    {
      "url": "https://www.digi.com/resources/security",
      "source": "e8a6bb0b-e373-42b1-a5de-93e314325576"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "e8a6bb0b-e373-42b1-a5de-93e314325576",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device."
    }
  ],
  "lastModified": "2026-10-06T15:08:38.397",
  "sourceIdentifier": "e8a6bb0b-e373-42b1-a5de-93e314325576"
}