important · Firmware
An unauthenticated adjacent-network request can execute commands as root across Digi’s DAL OS appliance portfolio.
Affects
Digi Accelerated Linux, the embedded operating system used across Digi cellular routers, gateways, device servers, and XBee gateway products.
The attacker needs adjacent-network reachability to an enabled DAL OS web-administration interface.
Detail and 3 sources
A crafted unauthenticated HTTP POST reaches an operating-system command context and executes commands as root.
The held material establishes neither a shipped correction nor a public execution demonstration.