PatchSiren

TOZED CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL TOZED CVE published 2026-10-11

CVE-2026-108576

A critical vulnerability was found in TOZED X300 up to 6.01.3, affecting the IPPingDiagnostics Handler's process_ping function, which is susceptible to os command injection. This issue allows remote attackers to execute arbitrary commands. The vendor, TOZED, was contacted but did not respond. The vulnerability has a high CVSS score of 10, indicating critical severity. Defenders should prioritize verifying [truncated]