important · Firmware — Privilege
An unauthenticated client on a Digi device’s default LAN can execute operating-system commands as root.
Affects
Digi Accelerated Linux, the embedded operating system used by Digi cellular routers, console servers, USB-over-IP devices and IoT gateways.
The administration service is LAN-only by default but can become WAN-reachable when reconfigured.
Detail and 2 sources
A crafted unauthenticated HTTP POST injects a command that runs with root privileges.
Today’s change is the recovery gap: affected devices still accept pre-fix images, preserving a route back to vulnerable code after an update.