<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>X300 (&lt;= 6.01.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/x300--6.01.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 14:01:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/x300--6.01.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in TOZED X300 via IPPingDiagnostics</title><link>https://feed.craftedsignal.io/briefs/2026-10-tozed-x300-rce/</link><pubDate>Sun, 11 Oct 2026 14:01:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tozed-x300-rce/</guid><description>An unauthenticated remote OS command injection vulnerability in the TOZED X300 IPPingDiagnostics Handler allows attackers to execute arbitrary code via the Host argument.</description><content:encoded><![CDATA[<p>The TOZED X300 device, in versions up to and including 6.01.3, contains a critical OS command injection vulnerability within the IPPingDiagnostics Handler component. Specifically, the process_ping function fails to properly sanitize the 'Host' argument before processing it, allowing a remote, unauthenticated attacker to inject and execute arbitrary operating system commands. Given that this vulnerability exists in a network-facing diagnostic function, it poses a significant risk for complete device takeover. TOZED has not provided a response or a patch as of the time of disclosure, making this an unmitigated risk for organizations deploying these devices in their infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-108576 results in remote code execution with the privileges of the underlying service process. This can lead to total device compromise, potential lateral movement into the local network, and the capability to intercept or manipulate traffic traversing the device. The impact is significant for any sector relying on TOZED X300 hardware for gateway or routing services.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for network and security teams:</p>
<ul>
<li>Implement strict ingress filtering to prevent unauthorized external access to the diagnostic interfaces of TOZED X300 devices.</li>
<li>Monitor for unusual traffic patterns targeting diagnostic or ping-related API endpoints on the X300.</li>
<li>If the device management interface is exposed, immediately move it to a management-only VLAN and restrict access to authorized IP ranges via firewall rules.</li>
<li>Since no patch is available, assess if these devices can be replaced or isolated from critical production segments until a security update is released by the vendor.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>