CVE-2026-56808Disclosure

LOWCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who can log in to the web management console of the affected product.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-30); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Active Exploitation · 2026-07-02: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 106-3007-02
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-021
Active Exploitation1
Full discourse2 posts
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    今朝のニュースを読んだ。 SharePointが悪用リストに入り、制御装置に穴が空き、サービス提供者が踏まれて10社超が道連れになった。 「影響なし」と言い切れる根拠があるか? ・SharePoint Server CVE-2026-45659、認証済みRCEをCISAがKEV登録 ・AVTECH DGM3103SCT CVE-2026-56808、OS命令注入でroot権限実行 ・三菱電機CNCシリーズ、細工パケットでDoS状態の脆弱性(JVNVU更新) ・加賀ソルネット「アカデミコナビ」、17万件の学生情報漏洩の可能性 ・メール配信「める配くん」不正アクセス、プリマハムら10社超に波及 ・NISC専門家会議、AI高度化に伴うサイバー脅威対策の強化を議論 サービス提供者が踏まれて利用企業が道連れになる手口は、もう珍しくない。 君の組織は「委託しているサービスのリスク」を把握しているか?

    Post summary

    Several newly disclosed CVEs, notably an authenticated RCE in SharePoint Server (CVE‑2026‑45659) and OS command injection in AVTECH devices, are being actively exploited in the wild, affecting more than ten companies, while no PoC, tool, or patch information is provided.

    0302672.5K
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56808 OS Command Injection in AVTECH DGM3103SCT Web Management Console https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56808

    Post summary

    The notice announces an OS command injection vulnerability (CVE-2026-56808) in the AVTECH DGM3103SCT Web Management Console, without any PoC, active exploitation, or patch information.

    00000135
    4.1K followersView on X

Explore more