As cited
Copy frozen at (site build).
vulnerabilities
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE - Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
The Tozed ZLT X300 5G customer premise equipment router firmware 6.01.3 contains an OS command injection vulnerability in its TR-069 client daemon that allows unauthenticated remote code execution as root via unsanitized parameters. An attacker with low-cost software-defined radio hardware can impersonate a carrier's configuration server to deliver malicious commands to affected devices.
Why it matters: Organizations and individuals using Tozed ZLT X300 5G CPE routers should verify their firmware version and patch immediately, as the CVSS 9.8 severity vulnerability enables complete device compromise without authentication through a rogue base station attack vector.
- Source published
- First seen by Cybersecurity Tracker