{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3htozedx300/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:tozed:x300:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-108576"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["X300 (\u003c= 6.01.3)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["TOZED"],"content_html":"\u003cp\u003eThe TOZED X300 device, in versions up to and including 6.01.3, contains a critical OS command injection vulnerability within the IPPingDiagnostics Handler component. Specifically, the process_ping function fails to properly sanitize the 'Host' argument before processing it, allowing a remote, unauthenticated attacker to inject and execute arbitrary operating system commands. Given that this vulnerability exists in a network-facing diagnostic function, it poses a significant risk for complete device takeover. TOZED has not provided a response or a patch as of the time of disclosure, making this an unmitigated risk for organizations deploying these devices in their infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-108576 results in remote code execution with the privileges of the underlying service process. This can lead to total device compromise, potential lateral movement into the local network, and the capability to intercept or manipulate traffic traversing the device. The impact is significant for any sector relying on TOZED X300 hardware for gateway or routing services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for network and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict ingress filtering to prevent unauthorized external access to the diagnostic interfaces of TOZED X300 devices.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual traffic patterns targeting diagnostic or ping-related API endpoints on the X300.\u003c/li\u003e\n\u003cli\u003eIf the device management interface is exposed, immediately move it to a management-only VLAN and restrict access to authorized IP ranges via firewall rules.\u003c/li\u003e\n\u003cli\u003eSince no patch is available, assess if these devices can be replaced or isolated from critical production segments until a security update is released by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T14:01:00Z","date_published":"2026-10-11T14:01:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tozed-x300-rce/","summary":"An unauthenticated remote OS command injection vulnerability in the TOZED X300 IPPingDiagnostics Handler allows attackers to execute arbitrary code via the Host argument.","title":"OS Command Injection in TOZED X300 via IPPingDiagnostics","url":"https://feed.craftedsignal.io/briefs/2026-10-tozed-x300-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:tozed:x300:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}