SECURITYCRITICALCVE-2026-105110

CVE-2026-105110: Iskratel Innbox GPON ONT Unauthenticated OS Command Injection

Unauthenticated OS command injection in Iskratel Innbox GPON ONT's login.xgi endpoint lets remote attackers execute commands as root.

Dylan H.

Security Team

October 9, 2026
4 min read
CVE-2026-105110: Iskratel Innbox GPON ONT Unauthenticated OS Command Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Iskratel Innbox GPON ONT devices (all firmware versions)

Overview

A critical, unauthenticated OS command injection vulnerability has been disclosed in Iskratel Innbox GPON Optical Network Terminal (ONT) devices, a line of fiber-to-the-home modems widely deployed by ISPs. Tracked as CVE-2026-105110 with a maximum-severity CVSS score of 9.8, the flaw lives in the login.xgi CGI endpoint — the component that handles authentication requests — and allows a remote attacker with no credentials to execute arbitrary commands as root via the CLI parameter.

Because the injection occurs during input processing, before any credential check completes, an attacker never needs a valid username or password to reach full device compromise.


Technical Details

FieldValue
CVE IDCVE-2026-105110
SeverityCritical (CVSS 9.8, CVSS 4.0 9.3)
CWECWE-78 — OS Command Injection; CWE-306 — Missing Authentication for Critical Function
Attack VectorNetwork
AuthenticationNone Required
Privileges RequiredNone
User InteractionNone
ImpactFull device compromise, arbitrary command execution as root
Affected VersionsAll Iskratel Innbox GPON ONT firmware (per vendor advisory)
Assigned ByTuranSec
Disclosed2026-10-08

How It Works

The login.xgi CGI script is meant to validate credentials submitted through the device's web management interface and, in many embedded GPON ONT firmware builds, runs with elevated (often root-equivalent) privileges to support administrative tasks like rebooting the device or pushing configuration changes.

The script fails to sanitize the CLI parameter before passing it to a system shell. An attacker who sends a crafted HTTP request containing shell metacharacters in that parameter gets those characters interpreted and executed by the underlying operating system alongside — or instead of — the intended login logic. Because this happens before authentication is enforced, no valid session, password, or token is ever needed.


Impact Assessment

Who Is At Risk

Any ISP or enterprise with Iskratel Innbox GPON ONT units deployed at the network edge, particularly where the device's management interface is reachable from the WAN side or from an untrusted internal segment. GPON ONTs sit at the boundary between a carrier's fiber network and a customer's local network, so a compromised unit gives an attacker a foothold with visibility into both sides.

Potential Attack Chains

  1. Discovery — Attacker fingerprints internet-facing or LAN-exposed Innbox ONT management interfaces (e.g. via Shodan-style scanning for the login.xgi endpoint)
  2. Exploitation — Attacker sends a single unauthenticated HTTP request with a malicious CLI parameter value
  3. Root Execution — The device executes the injected command as root, with no authentication ever checked
  4. Persistence and Pivot — Attacker installs a persistent backdoor, exfiltrates configuration/credentials, or uses the device as a relay point into the carrier or customer network

Mitigation

Immediate Actions

  • Restrict access to the ONT's management interface to trusted management VLANs only; never expose login.xgi or the broader web UI to the public internet
  • Monitor vendor channels for an official Iskratel firmware patch — none was available at time of disclosure
  • Segment affected devices from sensitive internal networks until a fix is applied

Detection Opportunities

  • Watch for unusual HTTP requests to login.xgi containing shell metacharacters (;, |, `, $(...)) in the CLI parameter
  • Monitor for unexpected outbound connections or configuration changes originating from ONT devices
  • Flag unexplained reboots or firmware behavior changes on fleet-managed ONT units

Defence-in-Depth

  • Apply network-level access control lists (ACLs) around all GPON ONT management planes, not just this device family
  • Maintain an inventory of edge/CPE device firmware versions to speed patch rollout once available
  • Treat CPE and ONT devices as untrusted network segments in zero-trust designs, rather than as trusted infrastructure

Discovery & Disclosure

CVE-2026-105110 was reserved on 2026-10-03 and published on 2026-10-08, assigned by TuranSec. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit has surfaced in open research repositories. Given the trivial, unauthenticated, zero-interaction attack path, defenders should not wait for confirmed in-the-wild exploitation before restricting exposure.


References