CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE - Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6780

As cited

Copy frozen at (site build).

vulnerabilities

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE - Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

The Tozed ZLT X300 5G customer premise equipment router firmware 6.01.3 contains an OS command injection vulnerability in its TR-069 client daemon that allows unauthenticated remote code execution as root via unsanitized parameters. An attacker with low-cost software-defined radio hardware can impersonate a carrier's configuration server to deliver malicious commands to affected devices.

Why it matters: Organizations and individuals using Tozed ZLT X300 5G CPE routers should verify their firmware version and patch immediately, as the CVSS 9.8 severity vulnerability enables complete device compromise without authentication through a rogue base station attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary