---
id: CVE-2026-75937
title: "A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device.\_Disable the web server when not conf…"
summary: "A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device.\_Disable the web server when not conf…"
severity: critical
cvss: 9.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'
cwe:
  - CWE-78
vendor: Digi International
product: IX Family
affected:
  - ix_family >= 21.8.24.139 <= 26.7.90.14
  - ex_family >= 21.8.24.139 <= 26.7.90.14
  - tx_family >= 21.8.24.139 <= 26.7.90.14
  - connect_it_family >= 21.8.24.139 <= 26.7.90.14
  - anywhereusb_plus_family >= 21.8.24.139 <= 26.7.90.14
  - connect_ez_family >= 21.8.24.139 <= 26.7.90.14
  - xbee_hive_gateway >= 21.8.24.139 <= 26.7.90.14
  - xbee_hive_border_router_for_wi-sun >= 21.8.24.139 <= 26.7.90.14
  - digi_54xx_family <= 21.8.24.139
  - digi_63xx_family >= 21.8.24.139 <= 22.5.50.66
  - digi_ix14 >= 21.8.24.139 <= 22.5.50.62
  - digi_lr54_family >= 21.8.24.139 <= 23.12.1.56
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T21:16:56.337'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75937'
references:
  - url: 'https://www.digi.com/resources/security'
    label: e8a6bb0b-e373-42b1-a5de-93e314325576
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T22:33:09.846Z'
---

## Overview

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
