OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-75937

CRITICAL · CVSS 9.4 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to send specially crafted HTTP POST requests to the web administration interface, enabling them to execute arbitrary operating system commands with root privileges. This poses a critical risk as it can lead to complete system compromise. Organizations using affected devices should prioritize immediate mitigation measures, including disabling the web server when not in use, to prevent exploitation.

CVE
CVE-2026-75937
Severity
CRITICAL
CVSS
9.4
EPSS
0.53%

Original NVD Description

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.