Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

TOZED X300 IPPingDiagnostics Handler Vulnerable to Remote OS Command Injection

Unpatched OS command injection in TOZED X300 firmware allows remote attackers to execute arbitrary commands via manipulated ping arguments.

TOZED X300 IPPingDiagnostics Handler Vulnerable to Remote OS Command Injection
Illustration: Firewall Pulse

Key points

  • CVE-2026-108576 affects TOZED X300 firmware versions up to 6.01.3
  • The flaw resides in the IPPingDiagnostics Handler process_ping function
  • National Vulnerability Database rates the vulnerability as critical severity

A remote operating system command injection flaw exists within the TOZED X300 device firmware. The vulnerability, identified as CVE-2026-108576, impacts the IPPingDiagnostics Handler component. Attackers can exploit this issue by manipulating the Host argument within the process_ping function. This manipulation enables the execution of arbitrary commands on the targeted system without requiring prior authentication.

Root cause

The underlying weakness stems from improper input validation within the network diagnostic tools. The process_ping function fails to sanitize the Host argument before passing it to the operating system shell. This oversight maps to Common Weakness Enumeration identifiers CWE-78 and CWE-77. These categories cover OS command injection and improper neutralisation of special elements respectively, indicating a fundamental failure in handling untrusted data.

Attack path

An attacker can launch this exploit remotely over the network. By crafting a request that sends a malicious payload via the Host argument, the adversary triggers the injection. The system processes this input as a valid command rather than a string. Consequently, the attacker gains the ability to run commands with the privileges of the service running the handler.

Affected versions

The vendor states that firmware versions prior to and including 6.01.3 are vulnerable. Specific affected releases include:

  • TOZED X300 version 6.01.0
  • TOZED X300 version 6.01.1
  • TOZED X300 version 6.01.2
  • TOZED X300 version 6.01.3

The National Vulnerability Database record confirms these versions lack the necessary input validation controls.

Mitigation

  • Segment networks to restrict external access to diagnostic interfaces
  • Monitor logs for unusual command execution patterns from ping utilities
  • Disable remote diagnostic features if they are not strictly required
  • Await a vendor patch, as no fix has been confirmed yet

What to do and how to stay safe: TOZED

  • Review firewall rules to block unsolicited traffic targeting the IPPingDiagnostics Handler ports
  • Implement strict input validation on any custom scripts interacting with the Host argument
  • Isolate affected TOZED X300 devices from critical internal networks pending a vendor update
  • Deploy intrusion detection signatures that alert on malformed ping requests containing shell characters

Step-by-step guide: Out-of-band patches: what small businesses need to know

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which specific versions of TOZED X300 firmware are affected by CVE-2026-108576?

Versions 6.01.0, 6.01.1, 6.01.2, and 6.01.3 are affected.

Is there a patch available to fix this command injection flaw?

No, the vendor did not respond to contact attempts, so no fix is confirmed.

What is the severity rating assigned by the National Vulnerability Database?

The NVD rates the vulnerability as critical.

Sources

  1. CVE Program
TOZEDX300CVE-2026-108576OS command injectionfirmware

Related stories