CRITICAL
TOZED
CVE published 2026-10-11
CVE-2026-108576
A critical vulnerability was found in TOZED X300 up to 6.01.3, affecting the IPPingDiagnostics Handler's process_ping function, which is susceptible to os command injection. This issue allows remote attackers to execute arbitrary commands. The vendor, TOZED, was contacted but did not respond. The vulnerability has a high CVSS score of 10, indicating critical severity. Defenders should prioritize verifying [truncated]