Cyber & AI intelligence
Wasteland.
Briefs indexed2354
Issues26
Published Mondays07:30 CT
CVE · High CVE-2026-83524 2026-08-31

CVE-2026-83524: Command Injection in RedPort Optimizer wXa Satellite Routers

"A publicly disclosed command injection flaw in the System Clock component of RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices allows remote, low-privileged attackers to execute arbitrary commands, and the vendor…"

A publicly disclosed command injection flaw in the System Clock component of RedPort Optimizer wXa-203, wXa-213, and wXa-223 devices allows remote, low-privileged attackers to execute arbitrary commands, and the vendor has not responded to the disclosure.

What Is It

CVE-2026-83524 is a command injection vulnerability (CWE-74 / CWE-77) in the exec function of /xgatev1/system/datetime.php, part of the System Clock component in RedPort Optimizer wXa firmware. Manipulation of input to that function leads to command injection. The attack can be initiated remotely over the network, requires low privileges, and needs no user interaction.

VulDB, the assigning CNA, rates the flaw at a CVSS 3.1 base score of 9.9 (CRITICAL): AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The CVSS 4.0 secondary score in the same record is 8.6 (HIGH) with exploit maturity rated Proof-of-Concept. The record was published by VulDB ([email protected]) on 2026-08-31 and is currently in "Received" status, meaning NVD has not yet completed its own analysis or published independent scoring.

Why It Matters

The exploit has been disclosed publicly and may be used. The changed-scope rating reflects impact beyond the vulnerable component itself: full confidentiality, integrity, and availability compromise of both the vulnerable system and downstream subsequent systems. Only a low-privilege foothold is needed to reach it.

The available source material does not confirm exploitation in the wild. VulDB's exploit maturity rating of Proof-of-Concept, combined with a public disclosure write-up, means working attack code is plausibly within reach of low-skill attackers even absent confirmed in-the-wild activity.

What's Vulnerable

Affected component: System Clock, via /xgatev1/system/datetime.php.

Patch Status

No patch is identified in the supplied source material. According to the VulDB entry, the vendor was contacted early about this disclosure but did not respond in any way. No vendor advisory, fixed version, or remediation guidance is available in the available data.

Sources