Five command-injection flaws disclosed in network and enterprise gear
0day Rubbish disclosed five unpatched command-injection issues in Cambium, Lantronix, MultiTech, Logo Netsis, and Server Technology products, scored 7.2 or 9.8, with no CVEs.
The 0day Rubbish Research Team published five Full Disclosure posts on 2026-09-27 describing command-injection flaws in separate products; none cites a CVE, a fix, or observed exploitation. Cambium cnMatrix EX3024F firmware 6.2.1-r4 is said to take COMMON_NAME from POST /iss/specific/ssl_digitalcert.html via HttpGetValuebyName after only percent-decoding, enabling root remote code execution, rated 7.2, with CWE-78, CWE-20, CWE-250, and CWE-269 cited. Lantronix SGX5150 firmware 9.13.0.0R7 has an authenticated injection in the FsBrowseClean path parameter, scored 7.2, that can run commands as root. MultiTech Conduit AEP 6.3.6 on mtcdt, mtcdtip, and mtcdtiphp gateways running mLinux allows an authenticated admin to inject through an import_config filename against a management API on TCP port 8080, also scored 7.2 and leading to root. Logo Netsis NetOpenX REST 2.0.6.9 is reported to have an unauthenticated SQL injection in its OAuth 2.0 token endpoint that can invoke SQL Server xp_cmdshell as SYSTEM, scored 9.8 and mapped to CWE-89, CWE-306, and CWE-78. A fifth post covers Server Technology (Legrand) PRO3X PDUs on firmware spdu-pro3x-030600 build 46640, where an authenticated attacker can override the port_mux listener and run commands as root (CWE-78, CWE-269), plus a separate hard-coded factory credential (CWE-798). The posts do not conflict because each concerns a different product.
- On 2026-09-27 the 0day Rubbish Research Team published five Full Disclosure posts; none cites a CVE, a fix, or in-the-wild exploitation.
- Cambium cnMatrix EX3024F firmware 6.2.1-r4: COMMON_NAME on POST /iss/specific/ssl_digitalcert.html is taken by HttpGetValuebyName after only percent-decoding, enabling root RCE, scored 7.2 (CWE-78, CWE-20, CWE-250, CWE-269).
- Lantronix SGX5150 firmware 9.13.0.0R7 (IT/OT device server): authenticated injection in the FsBrowseClean path parameter can run commands as root, scored 7.2 (CWE-78).
- MultiTech Conduit AEP 6.3.6 on mtcdt, mtcdtip, and mtcdtiphp gateways running mLinux: authenticated admin import_config filename injection against a management API on TCP port 8080 yields root, scored 7.2 (CWE-78).
- Logo Netsis NetOpenX REST 2.0.6.9 (Netsis Nox REST): unauthenticated SQL injection in the OAuth 2.0 token endpoint can invoke SQL Server xp_cmdshell as SYSTEM, scored 9.8 (CWE-89, CWE-306, CWE-78).
- Server Technology (Legrand) PRO3X PDUs, firmware spdu-pro3x-030600 build 46640 on ARM uClibc Linux: authenticated port_mux listener override can run commands as root, scored 7.2 (CWE-78, CWE-269); a separate hard-coded factory credential…
Coverage timelineoldest first · each row is one article
- · 3h ago[0day-rubbish] Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR COMMON_NAME command injection to root RCE (7.2)
Full Disclosure· 55
Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR field allows command injection to root RCE.
- · 3h ago[0day-rubbish] Lantronix SGX5150 9.13.0.0R7 Authenticated FsBrowseClean command injection to root RCE (7.2)
Full Disclosure· 42
Lantronix SGX5150 firmware has an authenticated command-injection flaw that can yield root code execution.
- · 3h ago