**Subject:** CVE-2026-2035703:... Note

Subject: CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

Posted by Surf free on Sep 08Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command injection vulnerability (CWE-78) in the TR-069/CWMP client daemon (netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into sprintf, which constructs a shell command executed via system_by_root() as root. An attacker operating a rogue LTE base station using SDR hardware (~$300) can impersonate the carrier's Auto Configuration Server and inject arbitrary...