CVE-2026-2686

CRITICAL

SECCN Dingcheng G10 3.1.0.181203 - Command Injection

Title source: llm

Description

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-77 CWE-78
Status draft

Timeline

Published Feb 19, 2026
Tracked Since Feb 19, 2026