CVE-2018-20162: Digi Transport LR54 Firmware

Critical severity, CVSS 9.9. EPSS: 4.1% chance of exploitation in the next 30 days.

Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.

Affected products

  • Digi Transport LR54 Firmware: before 4.4.0.26 (fixed in 4.4.0.26)

Published 2019-03-21. Last modified 2026-06-17.