Overview
A critical, unauthenticated OS command injection vulnerability has been disclosed in Iskratel Innbox GPON Optical Network Terminal (ONT) devices, a line of fiber-to-the-home modems widely deployed by ISPs. Tracked as CVE-2026-105110 with a maximum-severity CVSS score of 9.8, the flaw lives in the login.xgi CGI endpoint — the component that handles authentication requests — and allows a remote attacker with no credentials to execute arbitrary commands as root via the CLI parameter.
Because the injection occurs during input processing, before any credential check completes, an attacker never needs a valid username or password to reach full device compromise.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105110 |
| Severity | Critical (CVSS 9.8, CVSS 4.0 9.3) |
| CWE | CWE-78 — OS Command Injection; CWE-306 — Missing Authentication for Critical Function |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Full device compromise, arbitrary command execution as root |
| Affected Versions | All Iskratel Innbox GPON ONT firmware (per vendor advisory) |
| Assigned By | TuranSec |
| Disclosed | 2026-10-08 |
How It Works
The login.xgi CGI script is meant to validate credentials submitted through the device's web management interface and, in many embedded GPON ONT firmware builds, runs with elevated (often root-equivalent) privileges to support administrative tasks like rebooting the device or pushing configuration changes.
The script fails to sanitize the CLI parameter before passing it to a system shell. An attacker who sends a crafted HTTP request containing shell metacharacters in that parameter gets those characters interpreted and executed by the underlying operating system alongside — or instead of — the intended login logic. Because this happens before authentication is enforced, no valid session, password, or token is ever needed.
Impact Assessment
Who Is At Risk
Any ISP or enterprise with Iskratel Innbox GPON ONT units deployed at the network edge, particularly where the device's management interface is reachable from the WAN side or from an untrusted internal segment. GPON ONTs sit at the boundary between a carrier's fiber network and a customer's local network, so a compromised unit gives an attacker a foothold with visibility into both sides.
Potential Attack Chains
- Discovery — Attacker fingerprints internet-facing or LAN-exposed Innbox ONT management interfaces (e.g. via Shodan-style scanning for the
login.xgiendpoint) - Exploitation — Attacker sends a single unauthenticated HTTP request with a malicious
CLIparameter value - Root Execution — The device executes the injected command as root, with no authentication ever checked
- Persistence and Pivot — Attacker installs a persistent backdoor, exfiltrates configuration/credentials, or uses the device as a relay point into the carrier or customer network
Mitigation
Immediate Actions
- Restrict access to the ONT's management interface to trusted management VLANs only; never expose
login.xgior the broader web UI to the public internet - Monitor vendor channels for an official Iskratel firmware patch — none was available at time of disclosure
- Segment affected devices from sensitive internal networks until a fix is applied
Detection Opportunities
- Watch for unusual HTTP requests to
login.xgicontaining shell metacharacters (;,|,`,$(...)) in theCLIparameter - Monitor for unexpected outbound connections or configuration changes originating from ONT devices
- Flag unexplained reboots or firmware behavior changes on fleet-managed ONT units
Defence-in-Depth
- Apply network-level access control lists (ACLs) around all GPON ONT management planes, not just this device family
- Maintain an inventory of edge/CPE device firmware versions to speed patch rollout once available
- Treat CPE and ONT devices as untrusted network segments in zero-trust designs, rather than as trusted infrastructure
Discovery & Disclosure
CVE-2026-105110 was reserved on 2026-10-03 and published on 2026-10-08, assigned by TuranSec. As of publication, it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit has surfaced in open research repositories. Given the trivial, unauthenticated, zero-interaction attack path, defenders should not wait for confirmed in-the-wild exploitation before restricting exposure.