TOZED X300 IPPingDiagnostics Handler Vulnerable to Remote OS Command Injection
Unpatched OS command injection in TOZED X300 firmware allows remote attackers to execute arbitrary commands via manipulated ping arguments.

Key points
- CVE-2026-108576 affects TOZED X300 firmware versions up to 6.01.3
- The flaw resides in the IPPingDiagnostics Handler process_ping function
- National Vulnerability Database rates the vulnerability as critical severity
A remote operating system command injection flaw exists within the TOZED X300 device firmware. The vulnerability, identified as CVE-2026-108576, impacts the IPPingDiagnostics Handler component. Attackers can exploit this issue by manipulating the Host argument within the process_ping function. This manipulation enables the execution of arbitrary commands on the targeted system without requiring prior authentication.
Root cause
The underlying weakness stems from improper input validation within the network diagnostic tools. The process_ping function fails to sanitize the Host argument before passing it to the operating system shell. This oversight maps to Common Weakness Enumeration identifiers CWE-78 and CWE-77. These categories cover OS command injection and improper neutralisation of special elements respectively, indicating a fundamental failure in handling untrusted data.
Attack path
An attacker can launch this exploit remotely over the network. By crafting a request that sends a malicious payload via the Host argument, the adversary triggers the injection. The system processes this input as a valid command rather than a string. Consequently, the attacker gains the ability to run commands with the privileges of the service running the handler.
Affected versions
The vendor states that firmware versions prior to and including 6.01.3 are vulnerable. Specific affected releases include:
- TOZED X300 version 6.01.0
- TOZED X300 version 6.01.1
- TOZED X300 version 6.01.2
- TOZED X300 version 6.01.3
The National Vulnerability Database record confirms these versions lack the necessary input validation controls.
Mitigation
- Segment networks to restrict external access to diagnostic interfaces
- Monitor logs for unusual command execution patterns from ping utilities
- Disable remote diagnostic features if they are not strictly required
- Await a vendor patch, as no fix has been confirmed yet
What to do and how to stay safe: TOZED
- Review firewall rules to block unsolicited traffic targeting the IPPingDiagnostics Handler ports
- Implement strict input validation on any custom scripts interacting with the Host argument
- Isolate affected TOZED X300 devices from critical internal networks pending a vendor update
- Deploy intrusion detection signatures that alert on malformed ping requests containing shell characters
Step-by-step guide: Out-of-band patches: what small businesses need to know
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Which specific versions of TOZED X300 firmware are affected by CVE-2026-108576?
Versions 6.01.0, 6.01.1, 6.01.2, and 6.01.3 are affected.
Is there a patch available to fix this command injection flaw?
No, the vendor did not respond to contact attempts, so no fix is confirmed.
What is the severity rating assigned by the National Vulnerability Database?
The NVD rates the vulnerability as critical.



