External risk intelligence

Iskratel Innbox GPON ONT OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105110

The vulnerability affects a GPON ONT device, which is an internet edge gateway. The affected login endpoint is accessible via the network to unauthenticated users, placing this component directly on the public-facing edge of the network by design for management or service provider access.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in Iskratel Innbox GPON ONT devices involves an OS command injection flaw within the login endpoint. It allows unauthenticated remote attackers to execute arbitrary commands with root privileges, which could significantly compromise device security and potentially the wider network. The main concern is confirming relevance and exposure.

  • Unauthenticated remote command execution as root.
  • Matters due to device's network edge placement.
  • Confirm relevance and exposure for affected devices.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests over the network to the login endpoint on Iskratel Innbox GPON ONT devices. This access allows them to inject malicious commands through the CLI parameter, which are then executed with root privileges on the device.

  • Network access required.
  • Inject commands via the CLI parameter.
  • Execute arbitrary commands as root.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands as root on Iskratel Innbox GPON ONT devices when interacting with the login endpoint via the CLI parameter.

  • System commands executed as root.
  • Unauthenticated remote network access.
  • Complete device compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The exploitation of this OS command injection vulnerability in Iskratel Innbox GPON ONT devices likely falls under the responsibility of network or infrastructure teams, given the device's role as a network edge component. Immediate action should focus on identifying all deployed devices, assessing their exposure and criticality, and confirming the accountable owner for remediation planning.

  • Network and infrastructure teams own the issue.
  • Verify device reachability and criticality first.
  • Plan remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is an Iskratel Innbox GPON ONT?

An Iskratel Innbox GPON ONT is a device used in fiber-optic internet installations. It acts as the bridge between your service provider's fiber network and your local home or office network, converting optical signals into Ethernet connections for your routers and computers.

What does OS command injection mean for CVE-2026-105110?

This vulnerability, classified as CWE-78 (OS Command Injection), means an attacker can force the device to run unintended system-level commands. Because the system fails to properly validate input, unauthorized actors can inject instructions into the device's login process, granting them complete control as if they were a system administrator.

How is this vulnerability triggered?

An attacker triggers this by sending a specifically crafted network request to the device's login page using a parameter labeled 'CLI'. Importantly, this does not require a valid username or password; the system performs no authentication checks before executing the injected commands.

Why is this device considered high risk per Halo Surface Signal?

Halo Surface Signal identifies these devices as high-risk because they serve as internet edge gateways. Their design often requires the login portal to be reachable over the network for service provider maintenance, meaning these devices are frequently positioned directly at the network's public-facing edge.

Do I need to take action if I use this equipment?

Yes. Since this is a critical vulnerability affecting the device's root functions, you should identify all deployed Iskratel Innbox units in your infrastructure. Coordinate with your network team to assess how these devices are exposed to the internet and contact your service provider or the vendor to plan remediation.

References