CVE-2026-105110
Received Received - Intake

OS Command Injection in Iskratel Innbox GPON ONT

Vulnerability report for CVE-2026-105110, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: TuranSec

Description

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iskratel innbox_gpon_ont *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105110 is an OS Command Injection vulnerability in Iskratel Innbox GPON ONT devices. It allows unauthenticated remote attackers to execute arbitrary commands as root via the login.xgi CGI endpoint by manipulating the CLI parameter. The flaw occurs because user input is passed directly to a shell without proper sanitization or authentication checks.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to the /login.xgi endpoint with unusual CLI parameters. Use tools like curl to send test requests with harmless commands (e.g., 'echo test') and check for command output in publicly accessible directories. Example: curl 'http://<target-ip>/login.xgi?CLI=echo test' and inspect responses for command execution.

Impact Analysis

This vulnerability enables full device compromise. Attackers can gain root access, read or write files, extract credentials, and install persistent backdoors. Exploitation involves sending a crafted HTTP request with a command payload, which executes and stores output in a publicly accessible directory for retrieval.

Compliance Impact

This vulnerability allows unauthenticated remote code execution as root, enabling full device compromise. Such unauthorized access could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection requirements and HIPAA's security rules for protected health information.

Mitigation Strategies

Immediately restrict access to the /login.xgi endpoint via firewall rules or disable it if unused. Apply vendor patches if available. Implement strict input validation for all CGI parameters. Monitor for suspicious activity and unauthorized file modifications in web-accessible directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105110. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart