CVE-2026-25070CRITICAL 9.8EPSS p85.6%

CVE-2026-25070CVE-2026-25070

Description

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the destIp parameter to achieve remote code execution with root privileges on the network switch.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.00% probability of exploitation · percentile 85.6% · 2026-06-18T12:00:27Z
Published2026-03-07
Last modified2026-03-12

Underlying weaknesses· 1

CWE-78

References

  1. https://openwrt.org/toh/xikestor/sks8310-8x?s%5B%5D=xikestor&s%5B%5D=sks8310&s%5B%5D=8x
  2. https://www.aliexpress.com/i/3256808697772710.html

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-25072
CVE
CVE-2025-50526
CVE
CVE-2025-10401
CVE
CVE-2026-20764
CVE
CVE-2025-11097
CVE
D-Link DIR-820 Router OS Command Injection Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.