CVE-2026-56808

HIGH

Avtech Security Corporation DGM3103SCT - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-56808. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-56808, an OS command injection vulnerability in AVTECH Security Corporation's DGM3103SCT device. The code includes placeholder logic for probing the target but lacks actual exploit implementation or technical details about the injection vector.

Description

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who can log in to the web management console of the affected product.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-56808_dgm3103sct_provided_avtech.py

This repository contains an auto-generated stub module for CVE-2026-56808, an OS command injection vulnerability in AVTECH Security Corporation's DGM3103SCT device. The code includes placeholder logic for probing the target but lacks actual exploit implementation or technical details about the injection vector.

Classification
Stub 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: DGM3103SCT (AVTECH Security Corporation)
Auth required
Prerequisites: Valid credentials to log in to the target device · Network access to the device's web interface
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0155
EPSS Percentile 72.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
AVTECH Security Corporation/DGM3103SCT firmware version 3.2.5.4 and prior
Published Jun 30, 2026
Tracked Since Jun 30, 2026