TL;DR
Digi International disclosed CVE-2026-75937, a critical Digi DAL OS vulnerability scored 9.4 on CVSS 4.0. One crafted HTTP POST to the web admin interface can run commands as root. Digi has shipped patches for most devices, but several end-of-life models will never get one.
- CVE: CVE-2026-75937
- CVSS: 9.4 (Critical · CVSSv4)
- Product: Digi International IX Family
- Affected: 21.8.24.139, ≤ 21.8.24.139
- Impact: OS Command Injection in Digi Accelerated Linux (DAL OS)
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Digi Accelerated Linux (DAL OS) runs on Digi’s IX, EX, and TX cellular routers, Connect IT and Connect EZ console servers, AnywhereUSB hubs, and XBee gateways. The attacker needs no login. By default, only clients on the local LAN subnet can reach the web interface. However, Digi warns that customers who opened access to other subnets or the WAN face a CVSS 10.0 risk.
No public proof-of-concept or in-the-wild exploitation has been confirmed. Digi does not publish counts of affected devices.
How the Attack Works
The bug is an OS command injection (CWE-78) in the web administration service. Digi’s advisory states that “a specifically crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges.”
Affected Versions
The flaw affects DAL OS 21.8.24.139 through 26.7.90.14. Patched builds include:
- 26.2.148.166 LTS and 26.7.90.15 for most IX, EX, TX, and Connect IT models
- 26.2.148.166 LTS for AnywhereUSB Plus and Connect EZ devices
- 26.9.10.28 for the XBee Hive gateways and IX15
Meanwhile, the end-of-life 54xx, 63xx, IX14, and LR54 families will stay unpatched.
Patch and Mitigation Steps
Update affected devices now, as the Digi DAL OS command injection advisory urges. Afterward, change the admin password on every affected device and on any system sharing it.
Where patching is impossible, disable the web administration service when not configuring the device. Note that a Digi Remote Manager template may turn the service back on, so change the template too. Finally, prioritize devices that expose the web interface beyond the local LAN, since they face the highest risk from this Digi DAL OS vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!