THREAT OPS › Threat News › **Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
<p>Posted by Surf free on Sep 08</p>Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command<br /> injection vulnerability (CWE-78) in the TR-069/CWMP client daemon<br /> (netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into<br /> sprintf, which constructs a shell command executed via system_by_root() as<br /> root.<br /> <br /> An attacker operating a rogue LTE ba
Indicators of compromise
- CVE-2026-2035703cve
Original source: https://seclists.org/fulldisclosure/2026/Sep/32