CVE-2026-75937: Digi International Anywhereusb Plus Family
Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.
Affected products
- Digi International Anywhereusb Plus Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Connect Ez Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Connect It Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Digi 54xx Family: up to and including 21.8.24.139
- Digi International Digi 63xx Family: from 21.8.24.139, up to and including 22.5.50.66
- Digi International Digi IX14: from 21.8.24.139, up to and including 22.5.50.62
- Digi International Digi LR54 Family: from 21.8.24.139, up to and including 23.12.1.56
- Digi International Ex Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Ix Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Tx Family: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Xbee Hive Border Router For Wi-Sun: from 21.8.24.139, up to and including 26.7.90.14
- Digi International Xbee Hive Gateway: from 21.8.24.139, up to and including 26.7.90.14
Published 2026-10-02. Last modified 2026-10-06.