Digi · Dal Os · CVE-2026-75937
**Name of the Vulnerable Software and Affected Versions**
Digi DAL OS (affected versions not specified)
**Description**
An OS Command Injection flaw exists in the web administration interface. An unauthenticated attacker can send a specially crafted HTTP POST request to execute arbitrary operating system commands with root privileges on the device.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Disable the web server when not configuring the device.