DIGI International has disclosed a critical vulnerability in its Digi DAL OS (DAL OS) that affects the IX, EX and TX family of routers, Connect IT and Connect EZ devices, AnywhereUSB hubs, and XBee gateways. The flaw, tracked as CVE-2026-75937, enables an unauthenticated attacker to inject OS commands with root privileges via a specially crafted HTTP POST to the web administration interface.
The advisory states that by design the web admin interface is accessible only from the local LAN, but Digi notes that exposing the interface to other subnets or the WAN can raise the risk to CVSS 10.0 in affected deployments.
Evidence and affected versions indicate the vulnerability exists in DAL OS builds from 21.8.24[.]139 up to 26.7.90[.]14, with patches available in 26.2.148[.]166 LTS and 26.7.90[.]15 for most IX, EX, TX and Connect IT models, 26.2.148[.]166 LTS for AnywhereUSB Plus and Connect EZ devices, and 26.9.10[.]28 for XBee Hive gateways and IX15. End-of-life families (54xx, 63xx, IX14 and LR54) will remain unpatched.
Digi recommends updating affected devices promptly and then mandating a password change on all devices and systems sharing credentials. If patching is not possible, users should disable the web administration service when not configuring the device, bearing in mind that Remote Manager templates may re-enable it. Devices exposing the interface beyond the local LAN warrant the highest prioritisation.