CVE-2026-75937: unauthenticated root RCE in Digi routers scored 9.4
A critical flaw in the Digi Accelerated Linux (DAL OS) web administration service lets a crafted HTTP POST execute OS commands as root without authentication. Affected firmware spans 21.8.24.139 to 26.7.90.14; fixes ship in 26.2.148.166 LTS, 26.7.90.15 and 26.9.10.28.
- CVSS 4.0 score is 9.4, rising to 10.0 if the interface is exposed to WAN
- Affects IX, EX, TX, Connect IT, Connect EZ, AnywhereUSB and XBee devices
- Patched builds: 26.2.148.166 LTS, 26.7.90.15 and 26.9.10.28
- End-of-life 54xx, 63xx, IX14 and LR54 families get no fix
Read next
Security