External risk intelligence

TOZED X300 OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-108576

The TOZED X300 is a network appliance (router/gateway device). Diagnostics functions, such as IP ping utilities, are frequently exposed via the administrative web interface of such edge devices. Because these devices are designed to act as internet-facing gateways, an unauthenticated remote command injection vulnerability in a diagnostic handler is public-facing by design in normal deployment.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in TOZED X300 devices affecting a diagnostic function that allows for operating system command injection. This issue can be exploited remotely by unauthenticated attackers, posing a significant risk due to the nature of the affected technology. The main concern is confirming relevance and exposure, as the vendor has not responded to disclosure.

  • A diagnostic flaw allows remote attackers to run commands.
  • It impacts network devices, a critical infrastructure component.
  • Assess exposure and confirm if your systems are affected.

Attack Path

How an attacker could exploit the issue

An attacker can remotely exploit this vulnerability by sending a specially crafted request to the device's IP ping diagnostics handler. If the device processes this request without proper validation, it can lead to the execution of arbitrary operating system commands. This could potentially allow an attacker to compromise the affected device.

  • No authentication required for access.
  • Triggered by manipulating the 'Host' argument.
  • Results in operating system command injection.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability allows for remote command injection when a user or automated system interacts with the IPPingDiagnostics Handler's `process_ping` function. This could potentially affect the integrity and availability of the device's operating system and any services it provides, as an attacker could execute arbitrary commands.

  • System commands could be executed remotely.
  • Malicious commands could be injected via the `Host` argument.
  • Operating system compromise or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The TOZED X300's IP Ping Diagnostics Handler is susceptible to remote command injection, making it critical for infrastructure or platform teams to identify all deployments. The first practical step is to locate affected devices, assess their reachability and business criticality, identify the accountable owner, and then plan remediation based on risk.

  • Identify affected TOZED X300 deployments.
  • Verify external accessibility and business impact.
  • Plan coordinated vendor engagement or remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TOZED X300?

The TOZED X300 is a network appliance typically utilized as a router or gateway device. These devices manage network traffic at the edge of a environment, often providing administrative web interfaces that include diagnostic utilities for troubleshooting connectivity, such as ping tests.

What does CVE-2026-108576 mean?

This vulnerability is an OS Command Injection flaw, classified under CWE-77 and CWE-78. It means the software fails to properly sanitize input before passing it to the underlying operating system. An attacker can leverage this to execute unauthorized system-level commands, potentially taking full control of the device.

How is this command injection triggered?

The vulnerability is triggered by sending a specially crafted request to the IPPingDiagnostics Handler. By manipulating the 'Host' argument within the process_ping function, an attacker can inject malicious code. The bug is not triggered by normal, legitimate diagnostic traffic that uses valid, expected hostname formats.

Is my TOZED X300 at risk?

Halo Surface Signal indicates that because the TOZED X300 functions as an internet-facing gateway, diagnostic handlers are often exposed by design. If your device is directly connected to the internet rather than residing solely on an internal, protected network segment, it is significantly more likely to be reachable by unauthorized remote actors.

How should I respond to this threat?

Begin by creating an inventory of all TOZED X300 devices in your environment to understand your footprint. Prioritize verifying their network placement to determine if they are exposed externally. Since the vendor has not responded to the disclosure, coordinate with your infrastructure teams to assess the business impact and prepare for potential isolation or hardening measures.

References