important · Cellular — Tozed Router
A rogue LTE base station can make Tozed X300 routers execute shell commands as root.
Affects
Tozed ZLT X300 and X300A 5G CPE routers, cellular gateways running an aarch64 OpenWrt-derived firmware.
After a router attaches to the rogue cellular network, the attacker can impersonate the carrier’s TR-069 server and supply IPPingDiagnostics.Host.
Detail and 2 sources
netcwmpd inserts that value into a command passed to system_by_root() without validation, producing uid 0 shell execution. The researcher reproduced the chain on owned hardware and a private LTE network.
No patch is available.
Sources
Code / PoCTozed ZLT X300 5G CPE — Remote Root Code Execution via SDR Rogue Base Station · Advisory · danish1162/CVE-2026-2035703-x300 · GitHubSecondaryFull Disclosure: **Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)