ZeroHour
Full Disclosurepublished ()ingested

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

AI summary · glm-5.3-flash

Tozed ZLT X300 5G CPE firmware 6.01.3 has an unauthenticated TR-069 command injection (CVE-2026-2035703, CVSS 9.8) enabling root code execution.

Tozed ZLT X300 5G CPE router firmware 6.01.3 contains an OS command injection (CWE-78) in the TR-069/CWMP client daemon netcwmpd, tracked as CVE-2026-2035703 with CVSS 9.8. The IPPingDiagnostics Host parameter is passed unsanitized into sprintf, and the resulting shell command executes via system_by_root() as root. An attacker operating a rogue LTE base station built from roughly $300 of SDR hardware can impersonate the carrier's Auto Configuration Server and inject arbitrary commands. The disclosure does not report any observed exploitation.

  • CVE-2026-2035703: unauthenticated root RCE via TR-069 (CVSS 9.8)
  • IPPingDiagnostics Host parameter reaches a sprintf-built shell command
  • Exploitation requires a rogue LTE base station using ~$300 SDR hardware
  • Affects Tozed ZLT X300 5G CPE firmware 6.01.3 (CWE-78)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2035703

NVD description · AI analysis pending
Full article

Posted by Surf free on Sep 08 Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command injection vulnerability (CWE-78) in the TR-069/CWMP client daemon (netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into sprintf, which constructs a shell command executed via system_by_root() as root. An attacker operating a rogue LTE base station using SDR hardware (~$300) can impersonate the carrier's Auto Configuration Server and inject arbitrary...

This source does not provide full text. Read it at seclists.org.