Skip to finding
important · Firmware

An unauthenticated adjacent-network request can execute commands as root across Digi’s DAL OS appliance portfolio.

Affects

Digi Accelerated Linux, the embedded operating system used across Digi cellular routers, gateways, device servers, and XBee gateway products.

The attacker needs adjacent-network reachability to an enabled DAL OS web-administration interface.

Detail and 3 sources

A crafted unauthenticated HTTP POST reaches an operating-system command context and executes commands as root.

The held material establishes neither a shipped correction nor a public execution demonstration.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026