CVE-2018-20162: Digi Transport LR54 Firmware
Critical severity, CVSS 9.9. EPSS: 4.1% chance of exploitation in the next 30 days.
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.
Affected products
- Digi Transport LR54 Firmware: before 4.4.0.26 (fixed in 4.4.0.26)
Published 2019-03-21. Last modified 2026-06-17.