Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-22313: Authenticated Token Bypass on Device Management API

CVE-2026-22313
Summary

An attacker with a valid token on the management network can execute commands with admin privileges on the device. This could allow them to access or modify sensitive data. To protect against this, update the device with the latest software patch.

Original title
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbit...
Original description
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
nvd CVSS3.1 9.1
Vulnerability type
CWE-78 OS Command Injection
Published: 16 Jun 2026 · Updated: 20 Jul 2026 · First seen: 16 Jun 2026