CVE-2026-27559: Command Injection via GET in /api/status/data
Published Sep 16, 2026
·Updated
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
Event History
Sep 16, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this vulnerability?
The attacker must be able to reach the affected device remotely and authenticate with low-privileged user credentials. No user interaction is required.
2
What is the potential impact of successful exploitation?
A successful crafted GET request to /api/status/data can cause commands to run with root privileges on the device. This can result in complete compromise of the device’s confidentiality, integrity, and availability.